VulnerabilityModified
CVE-2007-0964
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
MEDIUM 5.4EPSS 1.49%
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
- CVSS 2.0
- 5.4 MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- cisco/firewall services module
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24172Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22561
- http://www.vupen.com/english/advisories/2007/0609
- http://secunia.com/advisories/24172Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22561
- http://www.vupen.com/english/advisories/2007/0609
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.