Vulnslist

find the latest Cisco vulnerabilities

Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software

cisco-sa-20070718-waas · Low · Published · Updated

The Cisco Wide Area Application Services (WAAS) software contains a denial of service (DoS) vulnerability that may cause some devices that run WAAS software (WAE appliance and NM-WAE-502 module) to stop processing all types of traffic, including data traffic and management traffic. This condition may occur if a device running WAAS software is configured for Edge Services, which utilizes Common Internet File System (CIFS) optimization and receives a flood of TCP SYN packets on port 139 or 445. Cisco has made free software available to address this vulnerability for affected customers. Workarounds are available to mitigate the effects of this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070718-waas.

Workarounds

No workaround information imported yet.

CVEsCVE-2007-3923
Cisco Bug IDsNA
CVSS ScoreBase 3.3
Product Names From Source
Cisco Wide Area Application Services (WAAS)

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Wide Area Application Services (WAAS) known_affected cisco_csaf CVE-2007-3923 1

Related Products

Product CVE Evidence
Cisco Wide Area Application Services (WAAS) CVE-2007-3923 Cisco OpenVuln
Cisco Wide Area Application Services Software CVE-2007-3923 Cisco OpenVuln