Vulnerability Name: | CVE-2007-0962 (CCN-32486) | ||||||||
Assigned: | 2007-02-14 | ||||||||
Published: | 2007-02-14 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0962 Source: OSVDB Type: UNKNOWN 33055 Source: CCN Type: SA24160 Cisco PIX and ASA Privilege Escalation and Denial of Service Source: SECUNIA Type: Vendor Advisory 24160 Source: CCN Type: SA24180 Cisco Firewall Services Module SIP DoS and ACL Corruption Source: SECUNIA Type: Patch, Vendor Advisory 24180 Source: CCN Type: SECTRACK ID: 1017651 Cisco ASA Lets Remote Users Deny Service and Remote Authenticated Users Gain Elevated Privileges Source: SECTRACK Type: Patch 1017651 Source: CCN Type: SECTRACK ID: 1017652 Cisco PIX Firewall Lets Remote Users Deny Service and Remote Authenticated Users Gain Elevated Privileges Source: CISCO Type: Patch, Vendor Advisory 20070214 Multiple Vulnerabilities in Firewall Services Module Source: CISCO Type: Patch, Vendor Advisory 20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances Source: CCN Type: cisco-sa-20070214-pix Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and ASA Appliances Source: CCN Type: OSVDB ID: 33055 Cisco PIX / ASA inspect http Malformed HTTP Traffic DoS Source: BID Type: UNKNOWN 22561 Source: CCN Type: BID-22561 Cisco Multiple Products Multiple Remote Denial Of Service Vulnerabilities Source: BID Type: UNKNOWN 22562 Source: CCN Type: BID-22562 Cisco PIX/ASA Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1017652 Source: VUPEN Type: UNKNOWN ADV-2007-0608 Source: XF Type: UNKNOWN cisco-pix-asa-http-dos(32486) Source: XF Type: UNKNOWN cisco-pix-asa-http-dos(32486) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
Vulnerability Name: | CVE-2007-0962 (CCN-32497) | ||||||||
Assigned: | 2007-02-14 | ||||||||
Published: | 2007-02-14 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0962 Source: CCN Type: SA24160 Cisco PIX and ASA Privilege Escalation and Denial of Service Source: CCN Type: SA24180 Cisco Firewall Services Module SIP DoS and ACL Corruption Source: CCN Type: SECTRACK ID: 1017651 Cisco ASA Lets Remote Users Deny Service and Remote Authenticated Users Gain Elevated Privileges Source: CCN Type: SECTRACK ID: 1017652 Cisco PIX Firewall Lets Remote Users Deny Service and Remote Authenticated Users Gain Elevated Privileges Source: CCN Type: cisco-sa-20070214-fwsm Cisco Security Advisory: Multiple Vulnerabilities in Firewall Services Module Source: CCN Type: OSVDB ID: 33055 Cisco PIX / ASA inspect http Malformed HTTP Traffic DoS Source: CCN Type: BID-22561 Cisco Multiple Products Multiple Remote Denial Of Service Vulnerabilities Source: CCN Type: BID-22562 Cisco PIX/ASA Privilege Escalation Vulnerability Source: XF Type: UNKNOWN cisco-fwsm-http-dos(32497) | ||||||||
BACK |