CVE-2003-1001
Last modified
CVE-2003-1001 is a vulnerability of currently unknown severity. Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Catalyst 6500 | All versions |
| Cisco | Catalyst 6500 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-1 | 3.1\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-2 | 3.1\(1a\) |
| Cisco | Catalyst 6500 Ws-X6380-Nam | 2.1\(2\) |
| Cisco | Catalyst 6500 Ws-X6380-Nam | 3.1\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-1 | 3.1\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-2 | 3.1\(1a\) |
| Cisco | Catalyst 7600 Ws-X6380-Nam | 2.1\(2\) |
| Cisco | Catalyst 7600 Ws-X6380-Nam | 3.1\(1a\) |
| Cisco | Firewall Services Module | All versions |
| Cisco | Firewall Services Module | 1.1.2 |
| Cisco | Catos | 5.4\(1\) |
| Cisco | Catos | 7.5\(1\) |
| Cisco | Catos | 7.6\(1\) |
References
- http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtmlPatch, Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20031215-fwsm.shtmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1001?
How severe is CVE-2003-1001?
How do I fix CVE-2003-1001?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0995Buffer overflow in the Microsoft Message Queue Manager (MSQM…
- CVE-2003-0996Unknown "System Security Vulnerability" in Computer Associat…
- CVE-2003-0997Unknown "Denial of Service Attack" vulnerability in Computer…
- CVE-2003-0998Unknown "potential system security vulnerability" in Compute…
- CVE-2003-0999Unknown multiple vulnerabilities in (1) lpstat and (2) the l…
- CVE-2003-1000xchat 2.0.6 allows remote attackers to cause a denial of ser…7.5
- CVE-2003-1002Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500…
- CVE-2003-1003Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remo…
- CVE-2003-1004Cisco PIX firewall 6.2.x through 6.2.3, when configured as a…
- CVE-2003-1005The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows r…
- CVE-2003-1006Buffer overflow in cd9660.util in Apple Mac OS X 10.0 throug…
- CVE-2003-1007AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 do…
Are you affected by CVE-2003-1001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
