cbcvebase.

Cisco Pix Firewall Software vulnerabilities

27 known vulnerabilities affecting cisco/pix_firewall_software.

Total CVEs
27
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM14

Vulnerabilities

Page 2 of 2
CVE-2005-3669P4MEDIUMCVSS 5.0v2.7v3.0+53 more2005-11-18
CVE-2005-3669 [MEDIUM] CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear whic
nvd
CVE-2006-4312P4MEDIUMCVSS 6.8v6.32006-08-23
CVE-2006-4312 [MEDIUM] CVE-2006-4312: Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when runn Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes
nvd
CVE-2003-0851P4MEDIUMCVSS 5.0v6.0v6.0\(1\)+16 more2003-12-01
CVE-2003-0851 [MEDIUM] CVE-2003-0851: OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
nvd
CVE-2003-1004P4MEDIUMCVSS 5.0v6.2v6.2\(1\)+3 more2004-01-05
CVE-2003-1004 [MEDIUM] CVE-2003-1004: Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.
nvd
CVE-2002-2139P4MEDIUMCVSS 6.4v6.0v6.0\(1\)+5 more2002-12-31
CVE-2002-2139 [MEDIUM] CVE-2002-2139: Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
nvd
CVE-1999-0158P4MEDIUMCVSS 5.0v4.1\(6\)v4.2\(1\)1998-08-31
CVE-1999-0158 [MEDIUM] CVE-1999-0158: Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM s Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
nvd
CVE-1999-0157P4MEDIUMCVSS 5.0v4.2\(1\)1998-08-18
CVE-1999-0157 [MEDIUM] CVE-1999-0157: Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
nvd
Cisco Pix Firewall Software vulnerabilities | cvebase