Executive Summary

Informations
Name CVE-2007-5580 First vendor Publication 2007-12-14
Vendor Cve Last vendor Modification 2018-10-15

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5580

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 18

Open Source Vulnerability Database (OSVDB)

Id Description
39521 Cisco Security Agent for Microsoft Windows Crafted SMB Packet Remote Overflow

A remote overflow exists in Cisco Security Agent. The HIPS fails to properly bounds check user input to SMB resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Information Assurance Vulnerability Management (IAVM)

Date Description
2007-12-19 IAVM : 2007-T-0052 - Cisco Security Agent for Windows Remote Buffer Overflow Vulnerability
Severity : Category I - VMSKEY : V0015592

Nessus® Vulnerability Scanner

Date Description
2008-05-02 Name : The remote Windows host has an application that is affected by a buffer overf...
File : cisco_csa_buffer_overflow.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/26723
BUGTRAQ http://www.securityfocus.com/archive/1/484669/100/100/threaded
CISCO http://www.cisco.com/en/US/products/products_security_advisory09186a008090a43...
CONFIRM http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetc...
MISC http://www.nsfocus.com/english/homepage/research/0702.htm
OSVDB http://osvdb.org/39521
SECTRACK http://www.securitytracker.com/id?1019046
SECUNIA http://secunia.com/advisories/27947
SREASON http://securityreason.com/securityalert/3425
VUPEN http://www.vupen.com/english/advisories/2007/4103

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2021-05-04 12:06:34
  • Multiple Updates
2021-04-22 01:07:06
  • Multiple Updates
2020-05-23 00:20:39
  • Multiple Updates
2018-10-16 00:19:18
  • Multiple Updates
2016-06-28 17:00:37
  • Multiple Updates
2016-04-26 16:44:05
  • Multiple Updates
2014-02-17 10:42:16
  • Multiple Updates
2013-11-11 12:37:47
  • Multiple Updates
2013-05-11 10:39:56
  • Multiple Updates