Orange Business Services
Vigil@nce Vigil@nce Vigil@nce
analyzing computer vulnerabilities since 1999
  home presentation vulnerabilities documentation contact  
subscriber area subscriber area
free access free access
The Vigil@nce team watches vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.
recent vulnerabilities recent vulnerabilities
tracked products tracked products
RSS feed RSS feed
vulnerability

vulnerability bulletin CVE-2013-1149 CVE-2013-1155

Cisco Catalyst, Router: multiple vulnerabilities of FWSM

Synthesis of the vulnerability

An attacker can use several vulnerabilities of the FWSM module of Cisco Catalyst 6500 and Cisco Router 7600.
Impacted products: Cisco Catalyst, Cisco Router xx00 Series.
Severity: 3/4.
Creation date: 11/04/2013.
Identifiers: BID-59001, BID-59002, CERTA-2013-AVI-240, cisco-sa-20130410-fwsm, CSCtg02624, CSCub85692, CSCud20267, CVE-2013-1149, CVE-2013-1155, VIGILANCE-VUL-12648.

Description of the vulnerability

Two vulnerabilities were announced in the FWSM module of Cisco Catalyst 6500 and Cisco Router 7600.

When the auth-proxy feature is enabled, an attacker can use a special url, in order to trigger a denial of service. [severity:3/4; BID-59002, CSCtg02624, CVE-2013-1155]

When IKE version 1 is enabled, an attacker can send a malformed message, in order to trigger a denial of service. [severity:3/4; BID-59001, CSCub85692, CSCud20267, CVE-2013-1149]
Complete Vigil@nce bulletin.... (free access)

Share this bulletin

Delicious Digg Facebook Google bookmarks LinkedIn Mail Reddit StumbleUpon Technorati Twitter 

Computer vulnerabilities tracking service

Vigil@nce provides a networks vulnerabilities workaround. Each administrator can customize the list of products for which he wants to receive vulnerability alerts. The Vigil@nce vulnerability database contains several thousand vulnerabilities. The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system.



















Copyright 1999-2014 Vigil@nce. Vigil@nce is a service from Orange Business Services. Site map. Legal notice. Version française