Multiple vulnerabilities have been identified in Cisco Firewall Services Module (FWSM), which could be exploited by attackers to cause a denial of service or bypass security restrictions.
The first issue is due to an error when inspecting a malformed HTTP request while enhanced HTTP inspection is enabled, which could be exploited by attackers to reload an affected device.
The second vulnerability is due to an error when inspecting malformed SIP packets while SIP inspection is enabled, which could be exploited by attackers to reload a vulnerable device.
The third issue is due to an error when processing a specially crafted packet for one of the device's IP addresses and generating syslog message 710006, which could be exploited by attackers to reload an affected device.
The fourth vulnerability is due to an error in the authentication for network access (auth-proxy) feature when handling invalid HTTPS requests, which could be exploited by attackers to reload a vulnerable device.
The fifth issue is due to an error in the authentication for network access (auth-proxy) feature when processing an overly long HTTP request, which could be exploited by attackers to reload an affected device.
The sixth vulnerability is due to an error in the HTTPS server when processing a particular type of HTTPS traffic directed to the FWSM itself, which could be exploited by attackers to reload a vulnerable device.
The seventh issue is due to an error when processing a malformed SNMP message sent from a trusted device, which could be exploited by attackers to reload an affected device.
The eighth vulnerability is due to an ACL corruption error when manipulating ACLs that make use of object groups, which may cause access control entries (ACEs) in an ACL to be evaluated out of order, or not to be evaluated.
Credits
Vulnerabilities reported by the vendor
ChangeLog
2007-02-15 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.