CVE-2010-2817
published 2010-08-09CVE-2010-2817: Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.50%
82.9th percentile
Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.10), and 8.3 before 8.3(1.1) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a crafted IKE message, aka Bug ID CSCte46507.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco·2010-08-04·CVSS 7.8
CVE-2010-1578 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by multiple vulnerabilities as follows:
Three SunRPC Inspection Denial of Service Vulnerabilities
Three Transport Layer Security (TLS) Denial of Service Vulnerabilities
Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerability
Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability
These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others.
There are workarounds for some of the vulnerabilities disclosed in this advisory.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/
Cisco
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
vendor_cisco
CVE-2010-2817 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
CVE-2010-2817: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by multiple vulnerabilities as follows: Three SunRPC Inspection Denial of Service Vulnerabilities Three Transport Layer Security (TLS) Denial of Service Vulnerabilities Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerability Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCtc77567, CSCtc79922, CSCtc85753, CSCtd32627, CSCtf37506
GHSA
GHSA-vqjf-hc9h-q7qc: Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7
ghsa_unreviewed·2022-05-14
CVE-2010-2817 [HIGH] GHSA-vqjf-hc9h-q7qc: Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7
Unspecified vulnerability in the IKE implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.10), and 8.3 before 8.3(1.1) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a crafted IKE message, aka Bug ID CSCte46507.
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id ASCII
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id ASCII"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004009; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T11
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UPDATE
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UPDATE"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004010; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T119
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id DELETE
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id DELETE"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004008; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T11
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UNION SELECT
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004006; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id INSERT
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id INSERT"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004007; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T11
Suricata
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2817 [HIGH] ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id SELECT
ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ol bookmarks SQL Injection Attempt -- index.php id SELECT"; flow:established,to_server; http.uri; content:"/read/index.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2817; reference:url,www.milw0rm.com/exploits/3964; classtype:web-application-attack; sid:2004005; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T11
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/40842http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtmlhttp://www.securityfocus.com/bid/42190http://secunia.com/advisories/40842http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtmlhttp://www.securityfocus.com/bid/42190
2010-08-09
Published