CVE-2007-2688: High severity Cisco Ips Sensor Software vulnerability
Published May 16, 2007
·Updated
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
Affected Software
23 affected components
Cisco Ips Sensor Software=4.0
Cisco Ips Sensor Software=5.0\(1\)
Cisco Ips Sensor Software=5.0\(2\)
Cisco Ips Sensor Software=5.0\(6\)p1
Cisco Ips Sensor Software=5.1\(1\)
Cisco Ips Sensor Software=5.1\(1a\)
Cisco Ips Sensor Software=5.1\(1b\)
Cisco Ips Sensor Software=5.1\(1c\)
Cisco Ips Sensor Software=5.1\(1d\)
Cisco Ips Sensor Software=5.1\(1e\)
Cisco Ips Sensor Software=5.1\(p1\)
Cisco IOS=10.0
Cisco IOS=11.1cc
Cisco IOS=11.3
Cisco IOS=12.0
Cisco IOS=12.0s
Cisco IOS=12.0st
Cisco IOS=12.0t
Cisco IOS=12.1
Cisco IOS=12.1e
Cisco IOS=12.1t
Cisco IOS=12.2
Cisco IOS=12.2t
Event History
May 16, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2688?
CVE-2007-2688 has a medium severity level due to potential evasion of HTTP traffic detection.
2
How do I fix CVE-2007-2688?
To resolve CVE-2007-2688, upgrade to a version of Cisco IPS Sensor Software or IOS that addresses this vulnerability.
3
What systems are affected by CVE-2007-2688?
CVE-2007-2688 affects multiple versions of Cisco IPS Sensor Software and IOS with Firewall/IPS Feature Set.
4
What types of attacks can exploit CVE-2007-2688?
Attackers can exploit CVE-2007-2688 to evade detection of malicious HTTP traffic.
5
Is there a vulnerability workaround for CVE-2007-2688?
A direct workaround for CVE-2007-2688 is not recommended; applying software updates is the best course of action.