PT-2000-1932 · Cisco · Cisco Secure Pix Firewall
Published
2000-12-11
·
Updated
2018-10-30
·
CVE-2000-1022
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Secure PIX Firewall versions 5.2(2) and earlier
Description
The issue concerns the mailguard feature, which fails to properly restrict access to SMTP commands. This allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.
Recommendations
For Cisco Secure PIX Firewall versions 5.2(2) and earlier, consider restricting access to the mailguard feature until a fix is available. As a temporary workaround, restrict the use of SMTP commands to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Secure Pix Firewall