>> Cisco PIX and ASA MGCP/TLS Remote Denial of Service Vulnerabilities
Title : Cisco PIX and ASA MGCP/TLS Remote Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3531 CVE ID : CVE-2007-5568 - CVE-2007-5569
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-10-18
Technical Description
Multiple vulnerabilities have been identified in Cisco PIX 500 Series Security Appliance (PIX) and Cisco 5500 Series Adaptive Security Appliance (ASA), which could be exploited by attackers to cause a denial of service.
The first issue is caused by an error in the Media Gateway Control Protocol (MGCP) application layer protocol inspection feature (disabled by default) when processing malformed packets sent to port 2427/UDP, which could be exploited by attackers to reload a vulnerable application, creating a denial of service condition.
The second vulnerability is caused by an error in the handling of specially crafted Transport Layer Security (TLS) packets, which could be exploited by attackers to reload a vulnerable application, creating a denial of service condition.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.