CVE-2013-1195: Medium severity cisco firewall services module software vulnerability
The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properly handle periodic statements for the time-range command, which allows remote attackers to bypass intended access restrictions by sending network traffic during denied time periods, aka Bug IDs CSCuf79091 and CSCug45850.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1195?
CVE-2013-1195 has a high severity rating due to its potential to allow unauthorized access to network resources.
How do I fix CVE-2013-1195?
To mitigate CVE-2013-1195, users should upgrade their Cisco ASA or FWSM devices to the latest software version provided by Cisco.
Which products are affected by CVE-2013-1195?
CVE-2013-1195 affects Cisco Adaptive Security Appliances and the Cisco Firewall Services Module.
What type of attack can exploit CVE-2013-1195?
CVE-2013-1195 can be exploited by attackers to bypass access restrictions via specially crafted network traffic.
Is there a workaround for CVE-2013-1195?
There are currently no official workarounds for CVE-2013-1195 other than applying the recommended software updates.