HIGH · 7.8

CVE-2011-3297

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attacker...

Vulnerability Description

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many authentication requests for network access, aka Bug ID CSCtn15697.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoFirewall Services Module Software3.1
CiscoCatalyst 6500All versions
CiscoCatalyst 7600All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-3297?

CVE-2011-3297 is a vulnerability with a CVSS score of 7.8 (HIGH). Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attacker...

How severe is CVE-2011-3297?

CVE-2011-3297 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-3297?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Firewall Services Module Software, Cisco Catalyst 6500, Cisco Catalyst 7600.