First published: Sat Jul 21 2007(Updated: )
The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wide Area Application Engine | ||
Cisco Wide Area Application Engine Nm-wae-502 | ||
Cisco Wide Area Application Services | =4.0.7 | |
Cisco Wide Area Application Services | =4.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3923 is classified as a denial of service vulnerability affecting certain versions of Cisco Wide Area Application Services.
To mitigate CVE-2007-3923, upgrade to Cisco Wide Area Application Services version 4.1 or later, which contains fixes for this vulnerability.
CVE-2007-3923 affects Cisco Wide Area Application Services versions 4.0.7 and 4.0.9.
Yes, CVE-2007-3923 can be exploited remotely, allowing attackers to cause a denial of service.
CVE-2007-3923 facilitates a denial of service attack that can lead to a loss of service for the affected applications.