Multiple Cisco FWSM Vulnerabilities
BID:9222
Info
Multiple Cisco FWSM Vulnerabilities
| Bugtraq ID: | 9222 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2003 12:00AM |
| Updated: | Dec 15 2003 12:00AM |
| Credit: | These issues were reported by Cisco. |
| Vulnerable: |
Cisco Firewall Services Module (FWSM) 1.1.2 Cisco Firewall Services Module (FWSM) 0 Cisco Catalyst 7600 3.1 (1a)WS-X6380-NAM Cisco Catalyst 7600 3.1 (1a)WS-SVC-NAM-2 Cisco Catalyst 7600 3.1 (1a)WS-SVC-NAM-1 Cisco Catalyst 7600 2.2 (1a)WS-SVC-NAM-2 Cisco Catalyst 7600 2.2 (1a)WS-SVC-NAM-1 Cisco Catalyst 7600 2.1 (2)WS-X6380-NAM Cisco Catalyst 6500 7.6 (1) Cisco Catalyst 6500 7.5 (1) Cisco Catalyst 6500 5.4.1 Cisco Catalyst 6500 3.1 (1a)WS-X6380-NAM Cisco Catalyst 6500 3.1 (1a)WS-SVC-NAM-2 Cisco Catalyst 6500 3.1 (1a)WS-SVC-NAM-1 Cisco Catalyst 6500 2.2 (1a)WS-SVC-NAM-2 Cisco Catalyst 6500 2.2 (1a)WS-SVC-NAM-1 Cisco Catalyst 6500 2.1 (2)WS-X6380-NAM Cisco Catalyst 6500 |
| Not Vulnerable: |
Cisco Firewall Services Module (FWSM) 1.1.3 |
Discussion
Multiple Cisco FWSM Vulnerabilities
Cisco has reported the following vulnerabilities in Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series and Cisco 7600 Series:
Cisco FWSM is prone to a buffer overrun vulnerability when handling HTTP Auth data. This would most likely result in a denial of service but could also potentially allow for arbitrary code execution (though this has not been confirmed).
Cisco FWSM has also been reported to be prone to denial of service attacks via SNMPv3 messages. This will cause a vulnerable device to reboot.
Both of these issues have been addressed in FWSM 1.1.3 and later for affected devices.
Cisco has reported the following vulnerabilities in Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series and Cisco 7600 Series:
Cisco FWSM is prone to a buffer overrun vulnerability when handling HTTP Auth data. This would most likely result in a denial of service but could also potentially allow for arbitrary code execution (though this has not been confirmed).
Cisco FWSM has also been reported to be prone to denial of service attacks via SNMPv3 messages. This will cause a vulnerable device to reboot.
Both of these issues have been addressed in FWSM 1.1.3 and later for affected devices.
Exploit / POC
Multiple Cisco FWSM Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Cisco FWSM Vulnerabilities
Solution:
This issue has been addressed in FWSM 1.1.3. The vendor has provided update instructions in the referenced advisory.
Solution:
This issue has been addressed in FWSM 1.1.3. The vendor has provided update instructions in the referenced advisory.