The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pix_firewall_software | Cisco | 4.2(1) (including) | 4.2(1) (including) |
Pix_firewall_software | Cisco | 4.2(2) (including) | 4.2(2) (including) |
Pix_firewall_software | Cisco | 4.2(5) (including) | 4.2(5) (including) |
Pix_firewall_software | Cisco | 4.3 (including) | 4.3 (including) |
Pix_firewall_software | Cisco | 4.4(4) (including) | 4.4(4) (including) |
Pix_firewall_software | Cisco | 5.0 (including) | 5.0 (including) |
Pix_firewall_software | Cisco | 5.1 (including) | 5.1 (including) |
Pix_firewall_software | Cisco | 5.2 (including) | 5.2 (including) |