CVE-2010-0566
published 2010-02-19CVE-2010-0566: Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.53%
83.1th percentile
Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10) allows remote attackers to cause a denial of service (device reload) via a malformed TCP segment when certain NAT translation and Cisco AIP-SSM configurations are used, aka Bug ID CSCtb37219.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500_series_adaptive_security_appliances | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco·2010-02-17·CVSS 7.8
CVE-2010-0149 [HIGH] CWE-287 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the
following vulnerabilities:
TCP Connection Exhaustion Denial of Service Vulnerability
Session Initiation Protocol (SIP) Inspection Denial of Service
Vulnerabilities
Skinny Client Control Protocol (SCCP) Inspection Denial of Service
Vulnerability
WebVPN Datagram Transport Layer Security (DTLS) Denial of Service
Vulnerability
Crafted TCP Segment Denial of Service Vulnerability
Crafted Internet Key Exchange (IKE) Message Denial of Service
Vulnerability
NT LAN Manager version 1 (NTLMv1) Authentication Bypass
Vulnerability
These vulnerabilities are not interdependent; a release that is
affected by one vulnerability is not necessarily affe
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco
CVE-2010-0566 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
CVE-2010-0566: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities: TCP Connection Exhaustion Denial of Service Vulnerability Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability Crafted TCP Segment Denial of Service Vulnerability Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability NT LAN Manager version 1 (NTLMv1) Authentication Bypass Vulnerability These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily
VulDB
Cisco ASA 5500 6.6.1164.0 denial of service (XFDB-56340 / SBV-24916)
vuldb·2026-05-01·CVSS 7.1
CVE-2010-0566 [HIGH] Cisco ASA 5500 6.6.1164.0 denial of service (XFDB-56340 / SBV-24916)
A vulnerability was found in Cisco ASA 5500 6.6.1164.0. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2010-0566. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-hghp-8wjq-vgpp: Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7
ghsa_unreviewed·2022-05-02
CVE-2010-0566 [HIGH] GHSA-hghp-8wjq-vgpp: Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7
Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10) allows remote attackers to cause a denial of service (device reload) via a malformed TCP segment when certain NAT translation and Cisco AIP-SSM configurations are used, aka Bug ID CSCtb37219.
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005168; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005166; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005169; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005164; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005167; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005165; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/62431http://secunia.com/advisories/38618http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtmlhttp://www.securityfocus.com/bid/38278http://www.securitytracker.com/id?1023612http://www.vupen.com/english/advisories/2010/0415https://exchange.xforce.ibmcloud.com/vulnerabilities/56340http://osvdb.org/62431http://secunia.com/advisories/38618http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtmlhttp://www.securityfocus.com/bid/38278http://www.securitytracker.com/id?1023612http://www.vupen.com/english/advisories/2010/0415https://exchange.xforce.ibmcloud.com/vulnerabilities/56340
2010-02-19
Published