Firewall Services Module

Vendor:

First CVE: Jan 5, 2004 · Active for 22 years

30
Total CVEs
More Total CVEs than 96% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Firewall Services Module over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 5, 2004
22 years ago
Most Recent CVE
Aug 18, 2016
3,627 days ago

CVE Severity & Scoring

Firewall Services Module30 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (3.3%)
Network1 (3.3%)
Unknown28 (93.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (6.7%)
High0 (0.0%)
Unknown28 (93.3%)
User Interaction
None2 (6.7%)
Unknown28 (93.3%)
Required0 (0.0%)
Privileges Required
Low1 (3.3%)
High0 (0.0%)
None1 (3.3%)
Unknown28 (93.3%)

Top CVEs

Signals from CVEs in this product scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bu
Aug 18, 20167.877YESYES
Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows rem
May 9, 20067.532NOYES
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t
Nov 23, 20047.529NONO
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.
Mar 15, 20127.824NONO
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), 8.2 before
Feb 25, 20117.823NONO
Unspecified vulnerability in the SunRPC inspection feature on the Cisco Firewall Services Module (FWSM) with software 3.1 before 3.1(17.2), 3.2 before 3.2(16.1), 4.0 before 4.0(10.
Aug 9, 20107.823NONO
Unspecified vulnerability in the SunRPC inspection feature on the Cisco Firewall Services Module (FWSM) with software 3.1 before 3.1(17.2), 3.2 before 3.2(16.1), 4.0 before 4.0(10.
Aug 9, 20107.823NONO
Unspecified vulnerability in the SunRPC inspection feature on the Cisco Firewall Services Module (FWSM) with software 3.1 before 3.1(17.2), 3.2 before 3.2(16.1), 4.0 before 4.0(10.
Aug 9, 20107.823NONO
Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evalua
Feb 16, 20079.023NONO
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi
Nov 23, 20045.023NONO

Exploit Exposure

Signals from CVEs in this product scope (30 CVEs).

CISA KEV
1 CVE
3.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (30 CVEs).

Media Mentions

Signals from CVEs in this product scope (30 CVEs).

Top CNAs Publishing CVEs For Firewall Services Module

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0\(6\)17.82.0%00
4.0\(4\)27.82.4%00
4.027.82.4%00
3.2\(3\)27.82.4%00
3.2\(2\)17.82.9%00
3.2\(1\)17.82.9%00
3.217.82.9%00
3.1\(6\)17.82.9%00
3.1\(5\)17.82.9%00
3.197.62.7%01
2.3\(1\)17.82.9%00
2.348.04.0%01
2.2\(1\)17.82.9%00
2.217.82.9%00
2.1_\(0.208\)56.17.0%00
1.1_\(3.005\)45.68.1%00
1.1.345.68.1%00
1.1.265.45.8%00