CVE Vulnerabilities

CVE-2011-3297

Improper Authentication

Published: Oct 06, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many authentication requests for network access, aka Bug ID CSCtn15697.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Firewall_services_module_softwareCisco3.1 (including)3.1 (including)
Firewall_services_module_softwareCisco3.1(2) (including)3.1(2) (including)
Firewall_services_module_softwareCisco3.1(3) (including)3.1(3) (including)
Firewall_services_module_softwareCisco3.1(4) (including)3.1(4) (including)
Firewall_services_module_softwareCisco3.1(5) (including)3.1(5) (including)
Firewall_services_module_softwareCisco3.1(6) (including)3.1(6) (including)
Firewall_services_module_softwareCisco3.1(7) (including)3.1(7) (including)
Firewall_services_module_softwareCisco3.1(8) (including)3.1(8) (including)
Firewall_services_module_softwareCisco3.1(9) (including)3.1(9) (including)
Firewall_services_module_softwareCisco3.1(10) (including)3.1(10) (including)
Firewall_services_module_softwareCisco3.1(11) (including)3.1(11) (including)
Firewall_services_module_softwareCisco3.1(12) (including)3.1(12) (including)
Firewall_services_module_softwareCisco3.1(13) (including)3.1(13) (including)
Firewall_services_module_softwareCisco3.1(14) (including)3.1(14) (including)
Firewall_services_module_softwareCisco3.1(15) (including)3.1(15) (including)
Firewall_services_module_softwareCisco3.1(16) (including)3.1(16) (including)
Firewall_services_module_softwareCisco3.1(17) (including)3.1(17) (including)
Firewall_services_module_softwareCisco3.1(18) (including)3.1(18) (including)
Firewall_services_module_softwareCisco3.1(19) (including)3.1(19) (including)
Firewall_services_module_softwareCisco3.1(20) (including)3.1(20) (including)
Firewall_services_module_softwareCisco3.2 (including)3.2 (including)
Firewall_services_module_softwareCisco3.2(1) (including)3.2(1) (including)
Firewall_services_module_softwareCisco3.2(2) (including)3.2(2) (including)
Firewall_services_module_softwareCisco3.2(3) (including)3.2(3) (including)
Firewall_services_module_softwareCisco3.2(4) (including)3.2(4) (including)
Firewall_services_module_softwareCisco3.2(5) (including)3.2(5) (including)
Firewall_services_module_softwareCisco3.2(6) (including)3.2(6) (including)
Firewall_services_module_softwareCisco3.2(7) (including)3.2(7) (including)
Firewall_services_module_softwareCisco3.2(8) (including)3.2(8) (including)
Firewall_services_module_softwareCisco3.2(9) (including)3.2(9) (including)
Firewall_services_module_softwareCisco3.2(10) (including)3.2(10) (including)
Firewall_services_module_softwareCisco3.2(11) (including)3.2(11) (including)
Firewall_services_module_softwareCisco3.2(12) (including)3.2(12) (including)
Firewall_services_module_softwareCisco3.2(13) (including)3.2(13) (including)
Firewall_services_module_softwareCisco3.2(14) (including)3.2(14) (including)
Firewall_services_module_softwareCisco3.2(15) (including)3.2(15) (including)
Firewall_services_module_softwareCisco3.2(16) (including)3.2(16) (including)
Firewall_services_module_softwareCisco3.2(17) (including)3.2(17) (including)
Firewall_services_module_softwareCisco3.2(18) (including)3.2(18) (including)
Firewall_services_module_softwareCisco3.2(19) (including)3.2(19) (including)
Firewall_services_module_softwareCisco3.2(20) (including)3.2(20) (including)
Firewall_services_module_softwareCisco3.2(21) (including)3.2(21) (including)
Firewall_services_module_softwareCisco4.0 (including)4.0 (including)
Firewall_services_module_softwareCisco4.0(1) (including)4.0(1) (including)
Firewall_services_module_softwareCisco4.0(2) (including)4.0(2) (including)
Firewall_services_module_softwareCisco4.0(3) (including)4.0(3) (including)
Firewall_services_module_softwareCisco4.0(4) (including)4.0(4) (including)
Firewall_services_module_softwareCisco4.0(5) (including)4.0(5) (including)
Firewall_services_module_softwareCisco4.0(6) (including)4.0(6) (including)
Firewall_services_module_softwareCisco4.0(7) (including)4.0(7) (including)
Firewall_services_module_softwareCisco4.0(8) (including)4.0(8) (including)
Firewall_services_module_softwareCisco4.0(10) (including)4.0(10) (including)
Firewall_services_module_softwareCisco4.0(11) (including)4.0(11) (including)
Firewall_services_module_softwareCisco4.0(12) (including)4.0(12) (including)
Firewall_services_module_softwareCisco4.0(13) (including)4.0(13) (including)
Firewall_services_module_softwareCisco4.0(14) (including)4.0(14) (including)
Firewall_services_module_softwareCisco4.0(15) (including)4.0(15) (including)
Firewall_services_module_softwareCisco4.1 (including)4.1 (including)
Firewall_services_module_softwareCisco4.1(1) (including)4.1(1) (including)
Firewall_services_module_softwareCisco4.1(2) (including)4.1(2) (including)
Firewall_services_module_softwareCisco4.1(3) (including)4.1(3) (including)
Firewall_services_module_softwareCisco4.1(4) (including)4.1(4) (including)
Firewall_services_module_softwareCisco4.1(5) (including)4.1(5) (including)
Firewall_services_module_softwareCisco4.1(6) (including)4.1(6) (including)

Potential Mitigations

References