CVE-2011-3297
published 2011-10-06CVE-2011-3297: Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.39%
69.1th percentile
Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many authentication requests for network access, aka Bug ID CSCtn15697.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module
vendor_cisco·2011-10-05·CVSS 7.8
CVE-2011-3296 [HIGH] CWE-287 Multiple Vulnerabilities in Cisco Firewall Services Module
Multiple Vulnerabilities in Cisco Firewall Services Module
The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500
Series switches and Cisco 7600 Series routers is affected by the following
vulnerabilities:
Syslog Message Memory Corruption Denial of Service
Vulnerability
Authentication Proxy Denial of Service Vulnerability
TACACS+ Authentication Bypass Vulnerability
Sun Remote Procedure Call (SunRPC) Inspection Denial of Service
Vulnerabilities
Internet Locator Server (ILS) Inspection Denial of Service
Vulnerability
These vulnerabilities are not interdependent; a release that is
affected by one vulnerability is not necessarily affected by the others.
Cisco has released software updates that address these vulnerabilities. Workarounds are available for some of the vulne
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module
vendor_cisco
CVE-2011-3297 Multiple Vulnerabilities in Cisco Firewall Services Module
CVE-2011-3297: Multiple Vulnerabilities in Cisco Firewall Services Module
The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers is affected by the following vulnerabilities: Syslog Message Memory Corruption Denial of Service Vulnerability Authentication Proxy Denial of Service Vulnerability TACACS+ Authentication Bypass Vulnerability Sun Remote Procedure Call (SunRPC) Inspection Denial of Service Vulnerabilities Internet Locator Server (ILS) Inspection Denial of Service Vulnerability These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-399, CWE-287, CWE-399
GHSA
GHSA-q23r-7gwj-52ch: Cisco Firewall Services Module (aka FWSM) 3
ghsa_unreviewed·2022-05-17
CVE-2011-3297 [HIGH] CWE-287 GHSA-q23r-7gwj-52ch: Cisco Firewall Services Module (aka FWSM) 3
Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many authentication requests for network access, aka Bug ID CSCtn15697.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-10-06
Published