Cisco Pix Firewall Software vulnerabilities
27 known vulnerabilities affecting cisco/pix_firewall_software.
Total CVEs
27
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM14
Vulnerabilities
Page 1 of 2
CVE-2006-0515P3HIGHCVSS 7.5PoCv2.7v3.0+55 more2006-05-09
CVE-2006-0515 [HIGH] CVE-2006-0515: Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3
Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspe
nvd
CVE-2000-1022P3HIGHCVSS 7.5PoCv4.2\(1\)v4.2\(2\)+6 more2000-12-11
CVE-2000-1022 [HIGH] CVE-2000-1022: The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict acc
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.
nvd
CVE-2000-1027P4MEDIUMCVSS 5.0PoCv5.22000-12-11
CVE-2000-1027 [MEDIUM] CVE-2000-1027: Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a targe
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.
nvd
CVE-2007-0960P3CRITICALCVSS 9.0v7.2\(2\)2007-02-16
CVE-2007-0960 [CRITICAL] CVE-2007-0960: Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when confi
Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2005-4499P3HIGHCVSS 7.5v2.7v3.0+55 more2005-12-22
CVE-2005-4499 [HIGH] CVE-2005-4499: The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL o
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS s
nvd
CVE-2003-1109P4HIGHCVSS 7.5v5.2\(1\)v5.2\(2\)+14 more2003-12-31
CVE-2003-1109 [HIGH] CVE-2003-1109: The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone m
The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
nvd
CVE-2007-0962P4HIGHCVSS 7.8v7.0v7.12007-02-16
CVE-2007-0962 [HIGH] CVE-2007-0962: Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1),
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.
nvd
CVE-2007-0959P4HIGHCVSS 7.8v7.2\(2\)2007-02-16
CVE-2007-0959 [HIGH] CVE-2007-0959: Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-
Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.
nvd
CVE-2007-0961P4HIGHCVSS 7.8v6.3v7.0+2 more2007-02-16
CVE-2007-0961 [HIGH] CVE-2007-0961: Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), an
Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v6.0v6.0\(1\)+20 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2013-0149P4MEDIUMCVSS 5.8v7.0v7.1+4 more2013-08-05
CVE-2013-0149 [MEDIUM] CVE-2013-0149: The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (ro
nvd
CVE-2000-0150P4HIGHCVSS 7.5v4.1\(6\)v4.1\(6b\)+5 more2000-02-12
CVE-2000-0150 [HIGH] CVE-2000-0150: Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server b
Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
nvd
CVE-2008-0028P4HIGHCVSS 7.1fixed in 7.2\(3\)6v8.0\(3\)2008-01-23
CVE-2008-0028 [HIGH] CVE-2008-0028: Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Securi
Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v6.0v6.0\(1\)+20 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2006-4194P4MEDIUMCVSS 5.0v6.32006-08-17
CVE-2006-4194 [MEDIUM] CVE-2006-4194: Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to sen
Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the vendor, after working with the researcher, has been unable to reproduce the issue
nvd
CVE-2003-1003P4HIGHCVSS 7.8v5.0v5.1+35 more2004-01-05
CVE-2003-1003 [HIGH] CWE-20 CVE-2003-1003: Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of servic
Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.
nvd
CVE-2004-0081P4MEDIUMCVSS 5.0v6.0v6.0\(1\)+20 more2004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2002-2140P4MEDIUMCVSS 5.0v5.2v5.2\(1\)+17 more2002-12-31
CVE-2002-2140 [MEDIUM] CVE-2002-2140: Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6
Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.
nvd
CVE-2006-3906P4MEDIUMCVSS 5.0v2.7v3.0+55 more2006-07-27
CVE-2006-3906 [MEDIUM] CVE-2006-3906: Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators,
Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a design weakness of the IKE version 1 protoc
nvd
CVE-2002-1024P4HIGHCVSS 7.1v5.2v5.3+3 more2002-10-04
CVE-2002-1024 [HIGH] CVE-2002-1024: Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of servi
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
nvd
1 / 2Next →