HIGH · 7.8

CVE-2007-3923

The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services...

Vulnerability Description

The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoWide Area Application EngineAll versions
CiscoWide Area Application Engine Nm-Wae-502All versions
CiscoWide Area Application Services4.0.7

References

FAQ

What is CVE-2007-3923?

CVE-2007-3923 is a vulnerability with a CVSS score of 7.8 (HIGH). The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services...

How severe is CVE-2007-3923?

CVE-2007-3923 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3923?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wide Area Application Engine, Cisco Wide Area Application Engine Nm-Wae-502, Cisco Wide Area Application Services.