<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"> 
  <channel>
  <title>Firewall Services Module Hot Issues from Cisco TAC</title>
  <link>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</link>
  <description>Hot Issues from Cisco TAC.  Please click the link for complete details.</description>
  <language>en-us</language>

  <managingEditor>wsisk@cisco.com (Wes Sisk)</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com (Cisco Newsroom)</webMaster>
  <pubDate>Mon, 13 May 2013 10:01:45 EDT</pubDate>
  <lastBuildDate>Mon, 13 May 2013 10:01:45 EDT</lastBuildDate>
  <generator>PERL</generator>

  <docs>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</docs>
  <ttl>10080</ttl>

<item>
<title>DOC: Zero-Downtime Upgrade Support Between Minor and Major Releases, Fixed CSCtr63007</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtr63007</link>
<description>&lt;B&gt;Symptom:&lt;/B&gt;

Current Firewall Services Module (FWSM) documentation states that downtime cannot be avoided when upgrading from a different major or minor software version in a failover environment. However, it is possible to perform an upgrade from the prior major and minor version combination to the next one with no failover interruption in 3.x and later software. This documentation defect is filed to correct the configuration guide.
&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

Running 3.x and later software.



</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtr63007</guid>
</item>
<item>
<title>Cisco FWSM time-range object may have no effect, Fixed CSCug45850</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug45850</link>
<description>&lt;b&gt;Symptoms:&lt;/b&gt;
The access-list is not effective when configured with a time-range object
&lt;br&gt;
&lt;b&gt;Conditions:&lt;/b&gt;
Currently this was noticed when the time-range object is configured with the &#39;&#39;periodic&#39;&#39; command and spanning over two or more consecutive days.
Example of affected configuration is:

time-range WEEKEND
  periodic Saturday 0:00 to Sunday 23:59

An access-list configured with the time-range object above will not have any effect.

To verify if you are affected by this issue, you can use the show time-range command while the time-range should be effective and verify that the
command show the rule as inactive:

ciscoasa#show time-range

time-range entry: WEEKEND (inactive)
    periodic Saturday 0:00 to Sunday 23:59
    used in: IP ACL entry
&lt;br&gt;

&lt;b&gt;Workaround:&lt;/b&gt;
Configuring the time-range object in a different way, may workaround this issue. Example of working configuration are:

time-range WEEKEND1
  periodic Saturday 0:00 to 23:59
  periodic Sunday 0:00 to 23:59

or

time-range WEEKEND2
  periodic weekend 0:00 to 23:59
&lt;br&gt;

&lt;b&gt;Further Problem Description:&lt;/b&gt;

A vulnerability in the implementation of the time-range object  could allow an unauthenticated, remote attacker to by-pass access-list that are
using the time-range option.

The vulnerability is due to improper implementation of the code for the time-range object, when the periodic command is used. Due to this issue
the time-range object will have no effect, thus depending on the access-list statement, (permit or deny), this may allow an attacker to by-pass
the access-list statement. An attacker could exploit this vulnerability by sending traffic through the affected system.

&lt;b&gt;PSIRT Evaluation:&lt;/b&gt;
The Cisco PSIRT has assigned this bug the following CVSS version 2 score. The Base and Temporal CVSS scores as of the time of evaluation are X/Y:
https://intellishield.cisco.com/security/alertmanager/cvssCalculator.do?dispatch=1&amp;version=2&amp;vector=AV:-/AC:-/Au:-/C:-/I:-/A:-/E:-/RL:-/RC:-
CVE ID CVE-2013-1195 has been assigned to document this issue.

Additional details about the vulnerability described here can be found at:
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1195

Additional information on Cisco&#39;s security vulnerability policy can be found at the following URL:
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug45850</guid>
</item>
   
</channel>
</rss>
