Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco Firewall Services Module

cisco-sa-20111005-fwsm · High · Published · Updated

The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers is affected by the following vulnerabilities: Syslog Message Memory Corruption Denial of Service Vulnerability Authentication Proxy Denial of Service Vulnerability TACACS+ Authentication Bypass Vulnerability Sun Remote Procedure Call (SunRPC) Inspection Denial of Service Vulnerabilities Internet Locator Server (ILS) Inspection Denial of Service Vulnerability These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others. Cisco has released software updates that address these vulnerabilities. Workarounds are available for some of the vulnerabilities disclosed in this advisory. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111005-fwsm. Note: Cisco ASA 5500 Series Adaptive Security Appliances and the Cisco Catalyst 6500 Series ASA Services Module are affected by some of the vulnerabilities described in this advisory. A separate Cisco Security Advisory has been published to disclose these and other vulnerabilities that affect the Cisco ASA 5500 Series Adaptive Security Appliances and the Cisco Catalyst 6500 Series ASA Services Module. The advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111005-asa.

Workarounds

This Cisco Security Advisory describes multiple distinct vulnerabilities. These vulnerabilities and their respective workarounds are independent of each other.
Syslog Message Memory Corruption Denial of Service Vulnerability
Completely disabling syslog 302015 with the command no logging message 302015 is an effective workaround for this vulnerability.
Authentication Proxy Denial of Service Vulnerability
There are no workarounds available for this vulnerability.
TACACS+ Authentication Bypass Vulnerability
There are no workarounds available for this vulnerability other than using a different authentication protocol such as RADIUS and LDAP.
SunRPC Inspection Denial of Service Vulnerabilities
Administrators can mitigate these vulnerabilities by disabling SunRPC inspection if it is not required. Administrators can disable SunRPC inspection by issuing the no inspect sunrpc command in class configuration sub-mode in the policy map configuration. Disabling SunRPC inspection may cause SunRPC traffic to stop transiting the security appliance.
ILS Inspection Denial of Service Vulnerability
Administrators can mitigate this vulnerability by disabling ILS inspection if it is not required. Administrators can disable ILS inspection by issuing the no inspect ils command in class configuration sub-mode in the policy map configuration. Disabling ILS inspection may cause ILS traffic to stop through the security appliance.

CVEsCVE-2011-3296, CVE-2011-3297, CVE-2011-3298, CVE-2011-3299, CVE-2011-3300, CVE-2011-3301, CVE-2011-3302, CVE-2011-3303
Cisco Bug IDsCSCti83875, CSCtn15697, CSCto74274, CSCtq09972, CSCtq09978, CSCtq09986, CSCtq09989, CSCtq57697, CSCtq57802
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco Firewall Services Module (FWSM), Cisco Adaptive Security Appliance (ASA) Software 7.2.2.34, Cisco Adaptive Security Appliance (ASA) Software 7.2.3.1, Cisco Adaptive Security Appliance (ASA) Software 7.2.2, Cisco Adaptive Security Appliance (ASA) Software 7.2.4, Cisco Adaptive Security Appliance (ASA) Software 7.2.3, Cisco Adaptive Security Appliance (ASA) Software 7.2.1, Cisco Adaptive Security Appliance (ASA) Software 7.2.4.27, Cisco Adaptive Security Appliance (ASA) Software 7.2.4.30, Cisco Adaptive Security Appliance (ASA) Software 7.2.5, Cisco Adaptive Security Appliance (ASA) Software 7.2.4.33, Cisco Adaptive Security Appliance (ASA) Software 8.0.2.11, Cisco Adaptive Security Appliance (ASA) Software 8.0.4, Cisco Adaptive Security Appliance (ASA) Software 8.0.3, Cisco Adaptive Security Appliance (ASA) Software 8.0.2, Cisco Adaptive Security Appliance (ASA) Software 8.0.1.2, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.25, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.28, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.33, Cisco Adaptive Security Appliance (ASA) Software 8.0.4.32, Cisco Adaptive Security Appliance (ASA) Software 8.0.5, Cisco Adaptive Security Appliance (ASA) Software 8.2.0.45, Cisco Adaptive Security Appliance (ASA) Software 8.2.1, Cisco Adaptive Security Appliance (ASA) Software 8.2.2, Cisco Adaptive Security Appliance (ASA) Software 8.2.2.10, Cisco Adaptive Security Appliance (ASA) Software 8.2.3, Cisco Adaptive Security Appliance (ASA) Software 8.2.4, Cisco Adaptive Security Appliance (ASA) Software 8.1.1, Cisco Adaptive Security Appliance (ASA) Software 8.1.2, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.15, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.16, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.19, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.23, Cisco Adaptive Security Appliance (ASA) Software 8.1.2.24, Cisco Adaptive Security Appliance (ASA) Software 8.3.1.1, Cisco Adaptive Security Appliance (ASA) Software 8.3.1, Cisco Adaptive Security Appliance (ASA) Software 8.3.2, Cisco Adaptive Security Appliance (ASA) Software 8.4.1, Cisco Adaptive Security Appliance (ASA) Software 8.4.2, Cisco Adaptive Security Appliance (ASA) Software 8.5.1, Cisco Adaptive Security Appliance (ASA) Software

Related Products

Product CVE Evidence
Cisco Firewall Services Module (FWSM) CVE-2011-3303 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3302 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3301 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3300 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3299 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3298 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3297 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2011-3296 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3303 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3302 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3301 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3300 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3299 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3298 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3297 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2011-3296 Cisco OpenVuln