CVE-2007-0965: High severity Cisco Firewall Services Module vulnerability
Published Feb 16, 2007
·Updated
Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.
Affected Software
1 affected component
Cisco Firewall Services Module=3.1
Remediation
Event History
Feb 16, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0965?
CVE-2007-0965 has a high severity rating as it can lead to a denial of service through device reboot.
2
How does CVE-2007-0965 affect Cisco FWSM?
CVE-2007-0965 affects Cisco FWSM versions 3.x before 3.1(3.2) when authentication is configured incorrectly.
3
What are the symptoms of the CVE-2007-0965 vulnerability?
Symptoms of CVE-2007-0965 include device reboots triggered by long HTTP requests.
4
How do I fix CVE-2007-0965?
To fix CVE-2007-0965, upgrade Cisco FWSM to version 3.1(3.2) or later.
5
Who is affected by CVE-2007-0965?
Organizations using Cisco Firewall Services Module software version 3.1 or earlier are affected by CVE-2007-0965.