First published: Wed Dec 17 2003(Updated: )
Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco PIX | =6.2.2_.111 | |
Cisco PIX Firewall | =5.1\(4.206\) | |
Cisco PIX Firewall | =5.1\(4\) | |
Cisco PIX Firewall | =5.2 | |
Cisco PIX Firewall | =5.3 | |
Cisco PIX Firewall | =5.3\(1\) | |
Cisco PIX Firewall | =5.3\(1.200\) | |
Cisco PIX Firewall | =6.0\(4.101\) | |
Cisco PIX Firewall | =6.0\(1\) | |
Cisco PIX Firewall | =5.1 | |
Cisco PIX Firewall | =6.0 | |
Cisco PIX Firewall | =6.0\(2\) | |
Cisco PIX Firewall | =6.1\(5\) | |
Cisco PIX Firewall | =6.3\(1\) | |
Cisco PIX Firewall | =5.3\(3\) | |
Cisco PIX Firewall | =6.2\(3\) | |
Cisco PIX Firewall | =6.2\(3.100\) | |
Cisco PIX Firewall | =5.2\(1\) | |
Cisco PIX Firewall | =5.2\(2\) | |
Cisco PIX Firewall | =6.1 | |
Cisco PIX Firewall | =6.1\(2\) | |
Cisco PIX Firewall | =5.2\(6\) | |
Cisco PIX Firewall | =5.2\(9\) | |
Cisco PIX Firewall | =6.0\(3\) | |
Cisco PIX Firewall | =6.1\(4\) | |
Cisco PIX Firewall | =6.2 | |
Cisco PIX Firewall | =6.3 | |
Cisco PIX Firewall | =5.2\(7\) | |
Cisco PIX Firewall | =6.0\(4\) | |
Cisco PIX Firewall | =6.1\(3\) | |
Cisco PIX Firewall | =5.0 | |
Cisco PIX Firewall | =5.3\(2\) | |
Cisco PIX Firewall | =6.2\(1\) | |
Cisco PIX Firewall | =6.2\(2\) | |
Cisco PIX Firewall | =5.2\(3.210\) | |
Cisco PIX Firewall | =5.2\(5\) | |
Cisco PIX Firewall | =6.1\(1\) | |
Cisco PIX Firewall | =6.3\(3.102\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1003 has a severity rating of high due to its capability to cause a complete denial of service on affected Cisco PIX firewalls.
To fix CVE-2003-1003, upgrade your Cisco PIX firewall to a version later than 6.3.1 or disable the SNMPv3 configuration.
CVE-2003-1003 affects Cisco PIX firewalls running versions 5.x.x and 6.3.1 and earlier.
CVE-2003-1003 involves a denial of service attack triggered by specially crafted SNMPv3 messages.
Yes, CVE-2003-1003 is a remote vulnerability that allows attackers to exploit the system from a distance.