Vulnerability Name:

CVE-2007-5570 (CCN-37251)

Assigned:2007-10-17
Published:2007-10-17
Updated:2019-08-01
Summary:Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.1 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-5570

Source: CCN
Type: SA27236
Cisco FWSM HTTPS/MGCP Packet Processing Denial of Service

Source: SECUNIA
Type: Third Party Advisory
27236

Source: CCN
Type: SECTRACK ID: 1018825
Cisco Firewall Service Module HTTPS and MGCP Processing Bugs Let Remote Users Deny Service

Source: CISCO
Type: Vendor Advisory
20071017 Multiple Vulnerabilities in Firewall Services Module

Source: CCN
Type: cisco-sa-20071017-fwsm
Multiple Vulnerabilities in Firewall Services Module

Source: CCN
Type: OSVDB ID: 37944
Cisco Firewall Services Module (FWSM) Crafted HTTPS Request Remote DoS

Source: BID
Type: Third Party Advisory, VDB Entry
26109

Source: CCN
Type: BID-26109
Cisco Firewall Services Module Multiple DoS and ACL Corruption Vulnerabilities

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1018825

Source: VUPEN
Type: Permissions Required
ADV-2007-3530

Source: XF
Type: Third Party Advisory, VDB Entry
cisco-fwsm-http-request-dos(37251)

Source: XF
Type: UNKNOWN
cisco-fwsm-http-request-dos(37251)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:cisco:firewall_services_module:*:*:*:*:*:*:*:* (Version >= 3.1 and <= 3.1(5))
  • OR cpe:/h:cisco:firewall_services_module:*:*:*:*:*:*:*:* (Version >= 3.2 and <= 3.2(1))

  • Configuration CCN 1:
  • cpe:/h:cisco:firewall_services_module:3.2(1):*:*:*:*:*:*:*
  • OR cpe:/h:cisco:firewall_services_module:3.1(5):*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco firewall services module *
    cisco firewall services module *
    cisco firewall services module 3.2(1)
    cisco firewall services module 3.1(5)