Cisco PIX Firewalls Vulnerable to SMTP Filtering Bypass
Secure PIX Firewalls that provide access to SMTP mail servers might let users bypass the firewall's SMTP command filtering.
September 27, 2001
ReportedSeptember 26, 2001, by Cisco Systems.
VERSION AFFECTED
Cisco Systems Secure PIX Firewalls with software versions 6.0(1), 5.2(5), and 5.2(4)
DESCRIPTION
Secure PIX Firewalls that provideaccess to SMTP mail servers might let users bypass the firewall's SMTP commandfiltering. In such events, intruders can gather information about email accountsor perform exploits against the mail server if that server has any existingvulnerabilities.
VENDOR RESPONSE
The vendor,Cisco Systems, is offering free software upgrades to remedy this vulnerabilityfor all affected customers. To obtain the fix, refer to Cisco'sbulletin regarding this matter.
CREDIT
Discoveredby Cisco Systems.
About the Author
You May Also Like