Cisco Firewall Services Module contains a flaw that may allow a remote denial of service. The issue is triggered when specially crafted HTTPS packets are directed to the FWSM it's HTTPS services, and will result in loss of availability for the system.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Workaround,
Upgrade
Exploit:
Exploit Rumored
Disclosure:
Vendor Verified
OSVDB:
Security Software
Technical
This vulnerability is only present when the HTTPS service is enabled on the FWSM. By default the HTTPS services is disabled.
Solution
Upgrade to FWSM version 3.1(3.18) or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s):
Disable the FWSM HTTPS server via 'no http server enable' or restrict traffic to trusted sources only.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.