CVE-2007-0964: Medium severity Cisco Firewall Services Module vulnerability
Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0964?
CVE-2007-0964 is considered a high severity vulnerability due to its potential to cause a denial of service condition.
How do I fix CVE-2007-0964?
To fix CVE-2007-0964, upgrade the Cisco Firewall Services Module to version 3.1(3.18) or later.
What systems are impacted by CVE-2007-0964?
CVE-2007-0964 affects Cisco Firewall Services Module versions prior to 3.1(3.18) when specific authentication configurations are used.
What type of attack does CVE-2007-0964 facilitate?
CVE-2007-0964 allows remote attackers to exploit a malformed HTTPS request to reboot the device.
Is there a permanent fix for CVE-2007-0964?
Yes, the permanent fix for CVE-2007-0964 is to upgrade to a patched version of the Cisco Firewall Services Module.