CVE-2007-0966: High severity Cisco Firewall Services Module vulnerability
Published Feb 16, 2007
·Updated
Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.
Affected Software
1 affected component
Cisco Firewall Services Module=3.1
Remediation
Event History
Feb 16, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0966?
CVE-2007-0966 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-0966?
To mitigate CVE-2007-0966, upgrade to Cisco Firewall Services Module version 3.1(3.11) or later.
3
What type of attack does CVE-2007-0966 exploit?
CVE-2007-0966 allows remote attackers to exploit the vulnerability by sending specific HTTPS traffic.
4
What is the impact of CVE-2007-0966?
The impact of CVE-2007-0966 includes a potential denial of service that causes the device to reboot.
5
Which Cisco products are affected by CVE-2007-0966?
CVE-2007-0966 affects the Cisco Firewall Services Module version 3.1 prior to 3.1(3.11) when the HTTPS server is enabled.