VulnerabilityModified
CVE-2007-5571
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.
MEDIUM 6.8EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/firewall services module
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/27236Third Party Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlVendor Advisory
- http://www.securityfocus.com/bid/26109Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018825Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3530Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37258Third Party Advisory, VDB Entry
- http://secunia.com/advisories/27236Third Party Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtmlVendor Advisory
- http://www.securityfocus.com/bid/26109Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018825Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3530Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37258Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.