CVE-2007-5580
published 2007-12-15CVE-2007-5580: Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.43%
92.9th percentile
Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent_for_windows_system_driver | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
vendor_cisco·2007-12-05·CVSS 10.0
CVE-2007-5580 [CRITICAL] CWE-119 Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in a system driver used by the
Cisco Security Agent for Microsoft Windows. This buffer overflow can be
exploited remotely and causes corruption of kernel memory, which leads to a
Windows stop error (blue screen) or to arbitrary code execution.
The vulnerability is triggered during processing of a crafted TCP
segment destined to TCP port 139 or 445. These ports are used by the Microsoft
Server Message Block (SMB) protocol.
Cisco has released software updates that address this vulnerability.
Common Vulnerabilities and Exposures (CVE) identifier CVE-2007-5580 has
been assigned to this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/ce
Cisco
Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
vendor_cisco
CVE-2007-5582 Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
CVE-2007-5582: Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in a system driver used by the Cisco Security Agent for Microsoft Windows. This buffer overflow can be exploited remotely and causes corruption of kernel memory, which leads to a Windows stop error (blue screen) or to arbitrary code execution. The vulnerability is triggered during processing of a crafted TCP segment destined to TCP port 139 or 445. These ports are used by the Microsoft Server Message Block (SMB) protocol. Cisco has released software updates that address this vulnerability. Common Vulnerabilities and Exposures (CVE) identifier CVE-2007-5580 has been assigned to this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com
Cisco
Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
vendor_cisco
CVE-2007-5580 Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
CVE-2007-5580: Cisco Security Agent for Windows System Driver Remote Buffer Overflow Vulnerability
A buffer overflow vulnerability exists in a system driver used by the Cisco Security Agent for Microsoft Windows. This buffer overflow can be exploited remotely and causes corruption of kernel memory, which leads to a Windows stop error (blue screen) or to arbitrary code execution. The vulnerability is triggered during processing of a crafted TCP segment destined to TCP port 139 or 445. These ports are used by the Microsoft Server Message Block (SMB) protocol. Cisco has released software updates that address this vulnerability. Common Vulnerabilities and Exposures (CVE) identifier CVE-2007-5580 has been assigned to this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com
GHSA
GHSA-pvxg-g7h5-249r: Buffer overflow in a certain driver in Cisco Security Agent 4
ghsa_unreviewed·2022-05-01
CVE-2007-5580 [HIGH] CWE-119 GHSA-pvxg-g7h5-249r: Buffer overflow in a certain driver in Cisco Security Agent 4
Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/39521http://secunia.com/advisories/27947http://securityreason.com/securityalert/3425http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsl00618http://www.cisco.com/en/US/products/products_security_advisory09186a008090a434.shtmlhttp://www.nsfocus.com/english/homepage/research/0702.htmhttp://www.securityfocus.com/archive/1/484669/100/100/threadedhttp://www.securityfocus.com/bid/26723http://www.securitytracker.com/id?1019046http://www.vupen.com/english/advisories/2007/4103http://osvdb.org/39521http://secunia.com/advisories/27947http://securityreason.com/securityalert/3425http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsl00618http://www.cisco.com/en/US/products/products_security_advisory09186a008090a434.shtmlhttp://www.nsfocus.com/english/homepage/research/0702.htmhttp://www.securityfocus.com/archive/1/484669/100/100/threadedhttp://www.securityfocus.com/bid/26723http://www.securitytracker.com/id?1019046http://www.vupen.com/english/advisories/2007/4103
2007-12-15
Published