Cisco PIX Firewalls Vulnerable to SMTP Filtering Bypass

Secure PIX Firewalls that provide access to SMTP mail servers might let users bypass the firewall's SMTP command filtering.

ITPro Today

September 27, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedSeptember 26, 2001, by Cisco Systems.

VERSION AFFECTED

  • Cisco Systems Secure PIX Firewalls with software versions 6.0(1), 5.2(5), and 5.2(4)

DESCRIPTION

Secure PIX Firewalls that provideaccess to SMTP mail servers might let users bypass the firewall's SMTP commandfiltering. In such events, intruders can gather information about email accountsor perform exploits against the mail server if that server has any existingvulnerabilities.

VENDOR RESPONSE

The vendor,Cisco Systems, is offering free software upgrades to remedy this vulnerabilityfor all affected customers. To obtain the fix, refer to Cisco'sbulletin regarding this matter.

CREDIT
Discoveredby Cisco Systems.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like