<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System Vulnerability through PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/system-vulnerability-through-pix/m-p/936896#M917042</link>
    <description>&lt;P&gt;The following vulnerability is showing up on systems when scanned through our PIX firewall(with all ICMP except echo-replies blocked).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.iss.net/security_center/reference/vuln/icmp-nofragment-lowmtu-dos.htm" target="_blank"&gt;http://www.iss.net/security_center/reference/vuln/icmp-nofragment-lowmtu-dos.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain why this would happen? The firewall should mitigate all vulnerabilities of this type since ICMP is blocked...&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:11:54 GMT</pubDate>
    <dc:creator>zztopping</dc:creator>
    <dc:date>2019-03-11T13:11:54Z</dc:date>
    <item>
      <title>System Vulnerability through PIX</title>
      <link>https://community.cisco.com/t5/network-security/system-vulnerability-through-pix/m-p/936896#M917042</link>
      <description>&lt;P&gt;The following vulnerability is showing up on systems when scanned through our PIX firewall(with all ICMP except echo-replies blocked).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.iss.net/security_center/reference/vuln/icmp-nofragment-lowmtu-dos.htm" target="_blank"&gt;http://www.iss.net/security_center/reference/vuln/icmp-nofragment-lowmtu-dos.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain why this would happen? The firewall should mitigate all vulnerabilities of this type since ICMP is blocked...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/system-vulnerability-through-pix/m-p/936896#M917042</guid>
      <dc:creator>zztopping</dc:creator>
      <dc:date>2019-03-11T13:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: System Vulnerability through PIX</title>
      <link>https://community.cisco.com/t5/network-security/system-vulnerability-through-pix/m-p/936897#M917043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jonathan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your PIX is only vulnerable if you are running 6.3 code or earlier and have IPsec enabled (which is not enabled by default). The vulnerability is due to CSCef57566. Also, I would recommend taking a look at the follow link, which has all the details of this vulnerability:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml" target="_blank"&gt;http://www.cisco.com/warp/public/707/cisco-sa-20050412-icmp.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround, you can disable IPSec, though this is probably not a viable solution for you. Therefore, to be protected against this vulnerability, you should upgrade to the latest 6.3.5.x interim release, or move to the 7.x or 8.x trains where this vulnerability does not exist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Aug 2008 01:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/system-vulnerability-through-pix/m-p/936897#M917043</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-16T01:24:11Z</dc:date>
    </item>
  </channel>
</rss>

