Cisco Firewall Services Module vulnerabilities
21 known vulnerabilities affecting cisco/firewall_services_module.
Total CVEs
21
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM7
Vulnerabilities
Page 1 of 2
CVE-2010-0151HIGHCVSS 7.8v4.0v4.0\(4\)+1 more2010-02-19
CVE-2010-0151 [HIGH] CVE-2010-0151: The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500
The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Client Control Protocol (SCCP) message.
nvd
CVE-2009-0638HIGHCVSS 7.8v2.1_\(0.208\)v2.2+12 more2009-08-21
CVE-2009-0638 [HIGH] CVE-2009-0638: The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 befor
The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 before 4.0(6) for Cisco Catalyst 6500 switches and Cisco 7600 routers allows remote attackers to cause a denial of service (traffic-handling outage) via a series of malformed ICMP messages.
nvd
CVE-2007-5584HIGHCVSS 7.8v3.2\(3\)2007-12-20
CVE-2007-5584 [HIGH] CVE-2007-5584: Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to
Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.2(3) allows remote attackers to cause a denial of service (device reload) via crafted "data in the control-plane path with Layer 7 Application Inspections."
nvd
CVE-2007-5568HIGHCVSS 7.1≤ 3.1\(5\)2007-10-18
CVE-2007-5568 [HIGH] CWE-20 CVE-2007-5568: Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM
Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).
nvd
CVE-2007-5570HIGHCVSS 7.8≥ 3.1, ≤ 3.1\(5\)≥ 3.2, ≤ 3.2\(1\)2007-10-18
CVE-2007-5570 [HIGH] CWE-20 CVE-2007-5570: Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cau
Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.
nvd
CVE-2007-5571MEDIUMCVSS 6.8≥ 3.1, ≤ 3.1\(6\)≥ 3.2, ≤ 3.2\(2\)2007-10-18
CVE-2007-5571 [MEDIUM] CWE-264 CVE-2007-5571: Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edit
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.
nvd
CVE-2007-0968CRITICALCVSS 9.0v2.3v3.12007-02-16
CVE-2007-0968 [CRITICAL] CVE-2007-0968: Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.
Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.
nvd
CVE-2007-0963HIGHCVSS 7.8v3.12007-02-16
CVE-2007-0963 [HIGH] CVE-2007-0963: Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to
Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as TCP or UDP, which triggers the reboot during generation of Syslog message 710006.
nvd
CVE-2007-0966HIGHCVSS 7.8v3.12007-02-16
CVE-2007-0966 [HIGH] CVE-2007-0966: Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows
Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.
nvd
CVE-2007-0965HIGHCVSS 7.8v3.12007-02-16
CVE-2007-0965 [HIGH] CVE-2007-0965: Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match"
Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.
nvd
CVE-2007-0967HIGHCVSS 7.8v3.12007-02-16
CVE-2007-0967 [HIGH] CVE-2007-0967: Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial
Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.
nvd
CVE-2007-0962HIGHCVSS 7.8v2.3v3.12007-02-16
CVE-2007-0962 [HIGH] CVE-2007-0962: Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1),
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.
nvd
CVE-2007-0964MEDIUMCVSS 5.4v3.12007-02-16
CVE-2007-0964 [MEDIUM] CVE-2007-0964: Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match"
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
nvd
CVE-2006-0515HIGHCVSS 7.5PoCv2.3v3.12006-05-09
CVE-2006-0515 [HIGH] CVE-2006-0515: Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3
Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspe
nvd
CVE-2005-3669MEDIUMCVSS 5.0v1.1.2v1.1.3+2 more2005-11-18
CVE-2005-3669 [MEDIUM] CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear whic
nvd
CVE-2005-1517HIGHCVSS 7.5≤ 2.3\(1\)2005-05-11
CVE-2005-1517 [HIGH] CVE-2005-1517: Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FT
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).
nvd
CVE-2004-0079HIGHCVSS 7.5v1.1.2v1.1.3+2 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2004-0081MEDIUMCVSS 5.0v1.1.2v1.1.3+2 more2004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2004-0112MEDIUMCVSS 5.0v1.1.2v1.1.3+2 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2003-1002MEDIUMCVSS 5.0v1.1.22004-01-05
CVE-2003-1002 [MEDIUM] CVE-2003-1002: Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote a
Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.
nvd
1 / 2Next →