Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Multiple Vulnerabilities in Cisco Firewall Services Module Software

cisco-sa-20130410-fwsm · High · Published · Updated

Cisco Firewall Services Module (FWSM) Software for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is affected by the following vulnerabilities: FWSM HTTP Proxy Traceback Vulnerability IKE Version 1 Denial of Service Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Successful exploitation of either of these vulnerabilities may result in a reload of an affected device, leading to a denial of service (DoS) condition. Cisco has released software updates that address these vulnerabilities. A workaround is available for the IKE vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-fwsm Note: The Cisco Adaptive Security Appliance (ASA) may be affected by some of the vulnerabilities listed above. A separate Cisco Security Advisory has been published to disclose the vulnerabilities that affect the Cisco ASA. That advisory is available at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-asa

Cisco advisory · CSAF JSON

Workarounds

Administrators can mitigate the  IKE Version 1 Denial of Service Vulnerability by disabling VPN access for administration and instead using SSH or HTTPS for administration.

CVEsCVE-2013-1149, CVE-2013-1155
Cisco Bug IDsCSCtg02624, CSCub85692, CSCud20267
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco Firewall Services Module (FWSM), Cisco Adaptive Security Appliance (ASA) Software 8.4.1, Cisco Adaptive Security Appliance (ASA) Software 8.4.2, Cisco Adaptive Security Appliance (ASA) Software 8.4.3, Cisco Adaptive Security Appliance (ASA) Software 8.4.4, Cisco Adaptive Security Appliance (ASA) Software 8.4.5, Cisco Adaptive Security Appliance (ASA) Software

Related Products

Product CVE Evidence
Cisco Firewall Services Module (FWSM) CVE-2013-1155 Cisco OpenVuln
Cisco Firewall Services Module (FWSM) CVE-2013-1149 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2013-1155 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2013-1149 Cisco OpenVuln