CVE-2013-1155
published 2013-04-11CVE-2013-1155: The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1)…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.26%
66.1th percentile
The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCtg02624.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module Software
vendor_cisco·2013-04-10·CVSS 7.8
CVE-2013-1149 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco Firewall Services Module Software
Multiple Vulnerabilities in Cisco Firewall Services Module Software
Cisco Firewall Services Module (FWSM) Software for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is affected by the following vulnerabilities:
FWSM HTTP Proxy Traceback Vulnerability
IKE Version 1 Denial of Service Vulnerability
These vulnerabilities are independent of each other; a release that is
affected by one of the vulnerabilities may not be affected by the
other.
Successful exploitation of either of these vulnerabilities may result in a
reload of an affected device, leading to a denial of service (DoS) condition.
Cisco has released software updates that address these vulnerabilities. A workaround is available for the IKE
vulnerability.
This advisory is available at the following link:
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module Software
vendor_cisco
CVE-2013-1155 Multiple Vulnerabilities in Cisco Firewall Services Module Software
CVE-2013-1155: Multiple Vulnerabilities in Cisco Firewall Services Module Software
Cisco Firewall Services Module (FWSM) Software for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is affected by the following vulnerabilities: FWSM HTTP Proxy Traceback Vulnerability IKE Version 1 Denial of Service Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Successful exploitation of either of these vulnerabilities may result in a reload of an affected device, leading to a denial of service (DoS) condition. Cisco has released software updates that address these vulnerabilities. A workaround is available for the IKE vulnerability. This advisory is available at the following li
GHSA
GHSA-rjgc-c55x-9463: The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3
ghsa_unreviewed·2022-05-17
CVE-2013-1155 [HIGH] CWE-287 GHSA-rjgc-c55x-9463: The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3
The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCtg02624.
No detection rules found.
No public exploits indexed.
2013-04-11
Published