PT-2007-2396 · Cisco · Cisco Pix 500+3

Publicado

2007-02-14

·

Atualizado

2018-10-30

·

CVE-2007-0961

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco PIX 500 and ASA 5500 Series Security Appliances versions 6.x through 6.3(5.114), 7.0 through 7.0(5.1), and 7.1 through 7.1(2.4) Cisco FWSM versions 3.x through 3.1(3.23)
Description: The issue allows remote attackers to cause a denial of service, resulting in a device reboot, via malformed SIP packets when the inspect sip option is enabled. This could lead to an unauthenticated, remote attacker causing a denial of service condition.
Recommendations: For Cisco PIX 500 and ASA 5500 Series Security Appliances versions 6.x through 6.3(5.114), update to version 6.3(5.115) or later. For Cisco PIX 500 and ASA 5500 Series Security Appliances versions 7.0 through 7.0(5.1), update to version 7.0(5.2) or later. For Cisco PIX 500 and ASA 5500 Series Security Appliances versions 7.1 through 7.1(2.4), update to version 7.1(2.5) or later. For Cisco FWSM versions 3.x through 3.1(3.23), update to version 3.1(3.24) or later. As a temporary workaround, consider disabling the inspect sip option until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0961

Produtos afetados

Cisco Asa 5500 Series Security Appliances
Cisco Asa
Cisco Fwsm
Cisco Pix 500