CVE-2013-5506
published 2013-10-13CVE-2013-5506: The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context mode is…
PriorityP423medium6.6CVSS 2.0
AVLACMAuSCCICAC
EPSS
0.28%
20.2th percentile
The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context mode is enabled, allows local users to read or modify any context's configuration via unspecified commands, aka Bug ID CSCue46080.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
| cisco | firewall_services_module_software | — | — |
CVSS provenance
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8fc-6rvq-p7r9: The authorization functionality in Cisco Firewall Services Module (FWSM) 3
ghsa_unreviewed·2022-05-17
CVE-2013-5506 [MEDIUM] GHSA-v8fc-6rvq-p7r9: The authorization functionality in Cisco Firewall Services Module (FWSM) 3
The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context mode is enabled, allows local users to read or modify any context's configuration via unspecified commands, aka Bug ID CSCue46080.
Cisco
Cisco Firewall Services Module Command Authorization Vulnerability
vendor_cisco·2013-10-09·CVSS 6.6
CVE-2013-5506 [MEDIUM] CWE-264 Cisco Firewall Services Module Command Authorization Vulnerability
Cisco Firewall Services Module Command Authorization Vulnerability
A vulnerability in the authorization code of the Cisco Firewall Services Module (FWSM) could allow an authenticated but unprivileged, local attacker to delete, modify, or view the configuration of any other context of the affected system.
The vulnerability is due to insufficient authorization safeguards of certain administrative commands in a user context when the affected system is configured for multiple context mode. An attacker could exploit this vulnerability by executing certain commands in any of the user contexts of the affected system.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
Only an attacker who could log in locally to the affected device could exploit the vu
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module Software
vendor_cisco·2013-10-09·CVSS 7.1
CVE-2013-5506 [HIGH] CWE-264 Multiple Vulnerabilities in Cisco Firewall Services Module Software
Multiple Vulnerabilities in Cisco Firewall Services Module Software
Cisco Firewall Services Module (FWSM) Software for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is affected by the following vulnerabilities:
Cisco FWSM Command Authorization Vulnerability
SQL*Net Inspection Engine Denial of Service Vulnerability
These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other.
Successful exploitation of the Cisco FWSM Command Authorization Vulnerability may result in a complete compromise of the confidentiality, integrity and availability of the affected system. Successful exploitation of the SQL*Net Inspection Engine Denial of Service Vulnerability may result in a reload of an affected
Cisco
Multiple Vulnerabilities in Cisco Firewall Services Module Software
vendor_cisco
CVE-2013-5506 Multiple Vulnerabilities in Cisco Firewall Services Module Software
CVE-2013-5506: Multiple Vulnerabilities in Cisco Firewall Services Module Software
Cisco Firewall Services Module (FWSM) Software for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is affected by the following vulnerabilities: Cisco FWSM Command Authorization Vulnerability SQL*Net Inspection Engine Denial of Service Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Successful exploitation of the Cisco FWSM Command Authorization Vulnerability may result in a complete compromise of the confidentiality, integrity and availability of the affected system. Successful exploitation of the SQL*Net Inspection Engine Denial of Service Vulnerability may result in a reload of a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-10-13
Published