Vulnerability Name:

CVE-2007-5568 (CCN-37257)

Assigned:2007-10-17
Published:2007-10-17
Updated:2018-10-30
Summary:Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
7.1 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-5568

Source: CCN
Type: SA27193
Cisco PIX and ASA TLS/MGCP Packet Processing Denial of Service

Source: SECUNIA
Type: UNKNOWN
27193

Source: CCN
Type: SA27236
Cisco FWSM HTTPS/MGCP Packet Processing Denial of Service

Source: SECUNIA
Type: UNKNOWN
27236

Source: CCN
Type: SECTRACK ID: 1018825
Cisco Firewall Service Module HTTPS and MGCP Processing Bugs Let Remote Users Deny Service

Source: CCN
Type: SECTRACK ID: 1018826
Cisco PIX Firewall TLS and MGCP Processing Bugs Let Remote Users Deny Service

Source: CCN
Type: SECTRACK ID: 1018827
Cisco ASA TLS and MGCP Processing Bugs Let Remote Users Deny Service

Source: CISCO
Type: UNKNOWN
20071017 Multiple Vulnerabilities in Cisco PIX and ASA Appliance

Source: CISCO
Type: UNKNOWN
20071017 Multiple Vulnerabilities in Firewall Services Module

Source: CCN
Type: cisco-sa-20071017-fwsm
Multiple Vulnerabilities in Firewall Services Module

Source: BID
Type: UNKNOWN
26104

Source: CCN
Type: BID-26104
Cisco PIX And ASA Appliances MGCP And TLS Packets Denial Of Service Vulnerabilities

Source: BID
Type: UNKNOWN
26109

Source: CCN
Type: BID-26109
Cisco Firewall Services Module Multiple DoS and ACL Corruption Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1018825

Source: SECTRACK
Type: UNKNOWN
1018826

Source: SECTRACK
Type: UNKNOWN
1018827

Source: VUPEN
Type: UNKNOWN
ADV-2007-3530

Source: VUPEN
Type: UNKNOWN
ADV-2007-3531

Source: XF
Type: UNKNOWN
cisco-fwsm-mgcp-dos(37257)

Source: XF
Type: UNKNOWN
cisco-fwsm-mgcp-dos(37257)

Source: XF
Type: UNKNOWN
cisco-asa-pix-mgcp-dos(37259)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:cisco:firewall_services_module:*:*:*:*:*:*:*:* (Version <= 3.1(5))

  • Configuration 2:
  • cpe:/a:cisco:adaptive_security_appliance_software:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(4):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(5):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(5.2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(6.7):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.5):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.27):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.48):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.49):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(1.22):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.7):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.8):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.10):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.14):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.15):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.16):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.17):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.19):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:adaptive_security_appliance_software:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:cisco:firewall_services_module:3.1(5):*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2007-5568 (CCN-37259)

    Assigned:2007-10-17
    Published:2007-10-17
    Updated:2018-10-30
    Summary:Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).
    CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): None
    Integrity (I): None
    Availibility (A): High
    CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
    5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    7.1 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
    5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Type:CWE-20
    Vulnerability Consequences:Denial of Service
    References:Source: MITRE
    Type: CNA
    CVE-2007-5568

    Source: CCN
    Type: SA27193
    Cisco PIX and ASA TLS/MGCP Packet Processing Denial of Service

    Source: CCN
    Type: SA27236
    Cisco FWSM HTTPS/MGCP Packet Processing Denial of Service

    Source: CCN
    Type: SECTRACK ID: 1018825
    Cisco Firewall Service Module HTTPS and MGCP Processing Bugs Let Remote Users Deny Service

    Source: CCN
    Type: SECTRACK ID: 1018826
    Cisco PIX Firewall TLS and MGCP Processing Bugs Let Remote Users Deny Service

    Source: CCN
    Type: SECTRACK ID: 1018827
    Cisco ASA TLS and MGCP Processing Bugs Let Remote Users Deny Service

    Source: CCN
    Type: cisco-sa-20071017-asa
    Multiple Vulnerabilities in Cisco PIX and ASA Appliances

    Source: CCN
    Type: BID-26104
    Cisco PIX And ASA Appliances MGCP And TLS Packets Denial Of Service Vulnerabilities

    Source: CCN
    Type: BID-26109
    Cisco Firewall Services Module Multiple DoS and ACL Corruption Vulnerabilities

    Source: XF
    Type: UNKNOWN
    cisco-asa-pix-mgcp-dos(37259)

    BACK
    cisco firewall services module *
    cisco adaptive security appliance software 7.0
    cisco adaptive security appliance software 7.0(4)
    cisco adaptive security appliance software 7.0(5)
    cisco adaptive security appliance software 7.0(5.2)
    cisco adaptive security appliance software 7.0(6.7)
    cisco adaptive security appliance software 7.0.1.4
    cisco adaptive security appliance software 7.0.4.3
    cisco adaptive security appliance software 7.1(2)
    cisco adaptive security appliance software 7.1(2.5)
    cisco adaptive security appliance software 7.1(2.27)
    cisco adaptive security appliance software 7.1(2.48)
    cisco adaptive security appliance software 7.1(2.49)
    cisco adaptive security appliance software 7.2(1)
    cisco adaptive security appliance software 7.2(1.22)
    cisco adaptive security appliance software 7.2(2)
    cisco adaptive security appliance software 7.2(2.7)
    cisco adaptive security appliance software 7.2(2.8)
    cisco adaptive security appliance software 7.2(2.10)
    cisco adaptive security appliance software 7.2(2.14)
    cisco adaptive security appliance software 7.2(2.15)
    cisco adaptive security appliance software 7.2(2.16)
    cisco adaptive security appliance software 7.2(2.17)
    cisco adaptive security appliance software 7.2(2.19)
    cisco adaptive security appliance software 8.0
    cisco firewall services module 3.1(5)