ID

VAR-200401-0042


CVE

CVE-2003-1001


TITLE

Cisco Catalyst 6500 and 7600 Buffer overflow vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200401-017

DESCRIPTION

Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication

Trust: 1.26

sources: NVD: CVE-2003-1001 // BID: 88192 // VULHUB: VHN-7826

AFFECTED PRODUCTS

vendor:ciscomodel:catalyst 6500 ws-svc-nam-2scope:eqversion:2.2\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 7600 ws-svc-nam-1scope:eqversion:3.1\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 6500 ws-x6380-namscope:eqversion:2.1\(2\)

Trust: 1.6

vendor:ciscomodel:catalyst 7600 ws-svc-nam-1scope:eqversion:2.2\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 6500 ws-svc-nam-1scope:eqversion:3.1\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 6500 ws-svc-nam-1scope:eqversion:2.2\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 6500 ws-x6380-namscope:eqversion:3.1\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 7600 ws-svc-nam-2scope:eqversion:2.2\(1a\)

Trust: 1.6

vendor:ciscomodel:catalyst 6500 ws-svc-nam-2scope:eqversion:3.1\(1a\)

Trust: 1.6

vendor:ciscomodel:firewall services modulescope:eqversion:1.1.2

Trust: 1.3

vendor:ciscomodel:catalyst 7600 ws-x6380-namscope:eqversion:3.1\(1a\)

Trust: 1.0

vendor:ciscomodel:catosscope:eqversion:5.4\(1\)

Trust: 1.0

vendor:ciscomodel:catosscope:eqversion:7.5\(1\)

Trust: 1.0

vendor:ciscomodel:catalyst 7600 ws-svc-nam-2scope:eqversion:3.1\(1a\)

Trust: 1.0

vendor:ciscomodel:catalyst 6500scope:eqversion:*

Trust: 1.0

vendor:ciscomodel:catosscope:eqversion:7.6\(1\)

Trust: 1.0

vendor:ciscomodel:firewall services modulescope:eqversion:*

Trust: 1.0

vendor:ciscomodel:catalyst 7600 ws-x6380-namscope:eqversion:2.1\(2\)

Trust: 1.0

vendor:ciscomodel:catalyst 6500scope: - version: -

Trust: 0.6

vendor:ciscomodel:catosscope:eqversion:7.5(1)

Trust: 0.3

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:76003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-2scope:eqversion:76003.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-x6380-namscope:eqversion:76002.1

Trust: 0.3

vendor:ciscomodel:catalyst ws-svc-nam-1scope:eqversion:65002.2

Trust: 0.3

vendor:ciscomodel:catalystscope:eqversion:6500

Trust: 0.3

sources: BID: 88192 // CNNVD: CNNVD-200401-017 // NVD: CVE-2003-1001

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-1001
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200401-017
value: MEDIUM

Trust: 0.6

VULHUB: VHN-7826
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2003-1001
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-7826
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-7826 // CNNVD: CNNVD-200401-017 // NVD: CVE-2003-1001

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-1001

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200401-017

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200401-017

EXTERNAL IDS

db:NVDid:CVE-2003-1001

Trust: 2.0

db:CNNVDid:CNNVD-200401-017

Trust: 0.7

db:CISCOid:20031215 CISCO FWSM VULNERABILITIES

Trust: 0.6

db:BIDid:88192

Trust: 0.3

db:VULHUBid:VHN-7826

Trust: 0.1

sources: VULHUB: VHN-7826 // BID: 88192 // CNNVD: CNNVD-200401-017 // NVD: CVE-2003-1001

REFERENCES

url:http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtml

Trust: 2.0

sources: VULHUB: VHN-7826 // BID: 88192 // CNNVD: CNNVD-200401-017 // NVD: CVE-2003-1001

CREDITS

Unknown

Trust: 0.3

sources: BID: 88192

SOURCES

db:VULHUBid:VHN-7826
db:BIDid:88192
db:CNNVDid:CNNVD-200401-017
db:NVDid:CVE-2003-1001

LAST UPDATE DATE

2024-08-14T13:40:23.766000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-7826date:2008-09-10T00:00:00
db:BIDid:88192date:2016-07-06T14:33:00
db:CNNVDid:CNNVD-200401-017date:2005-10-20T00:00:00
db:NVDid:CVE-2003-1001date:2008-09-10T19:21:24.353

SOURCES RELEASE DATE

db:VULHUBid:VHN-7826date:2004-01-05T00:00:00
db:BIDid:88192date:2004-01-05T00:00:00
db:CNNVDid:CNNVD-200401-017date:2004-01-05T00:00:00
db:NVDid:CVE-2003-1001date:2004-01-05T05:00:00