39298 : Cisco Firewall Services Module (FWSM) Unspecified Remote DoS
Printer | http://osvdb.org/39298 | Email This | Edit Vulnerability

Views This Week

2

Views All Time

207

Info

Last Modified

about 1 year ago

Percent Complete

90%

Disclosure

Dec 19, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jan 07, 2008

Keywords

CSCsl08519

Description

Cisco Firewall Services Module (FWSM) contains a flaw that may allow a remote denial of service. The issue is triggered when certain unspecified standard network traffic is processed by the layer 7 application inspection engine, and will result in loss of availability for the system.

Classification

Location: Remote/Network Access Required
Attack Type: Denial of Service
Impact: Loss of Availability
Solution: Workaround, Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Security Software

Solution

Upgrade to version 3.2(4) or higher, as it has been reported to fix this vulnerability. It is also possible to mitigate against the flaw by implementing the following workaround:

Disable the TCP normalizing function, which is enabled by default.

Products

Cisco Systems, Inc.
Watch-list
Firewall Services Module (FWSM)
Watch-list
3.2(3)

References

Credit

Unknown or Incomplete

Blogs

2007/12/27 14:26:04 | Software design in network appliances

from: EONSEC

Creating an ASIC for inspecting TCP/IP payloads is suboptimal. A software based design is better for maintenance and flexibility. Such a design is employed by Cisco FWSM. Common Vulnerabilities and Exposures (CVE) identifier CVE-2007-5584 summarizes a recent Cisco vulnerability. An excerpt from the vendor's advisory

2007/12/20 17:14:07 | Cisco Firewall Services Module Denial of Service Vulnerability - Advisories - Secunia

from: Chris Mosby at myITforum.com

Cisco Firewall Services Module Denial of Service Vulnerability - Advisories - Secunia Cisco Firewall Services Module Denial of Service ... reference: CVE-2007-5584 (Secunia mirror) Description: A vulnerability has been reported in the Cisco

2007/12/19 19:08:00 | App Inspection Vuln in Cisco Firewall Services

from: Liquidmatrix Security Digest

This just in from the folks at Cisco: A vulnerability exists in the Cisco Firewall Services Module (FWSM) ... Vulnerabilities and Exposures (CVE) identifier CVE-2007-5584 has been assigned to this vulnerability

2007/12/19 16:39:21 | [Full-disclosure] Cisco Security Advisory: Application Inspection Vulnerability in Cisco Firewall Services Module

from: Full-Disclosure digest, knowledge base

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: ... this vulnerability. Common Vulnerabilities and Exposures (CVE) identifier CVE-2007-5584

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use