<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos pixos-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:32:23.825-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5983" version="1" class="vulnerability">
      <metadata>
        <title>Cisco PIX and ASA Windows NT Domain Authentication Bypass Vulnerability</title>
        <affected family="pixos">
          <platform>Cisco PIX</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3815"/>
        <description>Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:57.007-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:38.836-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:04.290-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco PIX meets CVE-2008-3815">
        <criterion comment="PIX vulnerable versions" test_ref="oval:org.mitre.oval:tst:9247"/>
        <criterion comment="config contains: nt-auth-domain-controller" test_ref="oval:org.mitre.oval:tst:9139"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5597" version="1" class="vulnerability">
      <metadata>
        <title>Cisco ASA and PIX Crypto Accelerator Memory Leak Vulnerability</title>
        <affected family="pixos">
          <platform>Cisco PIX</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3817"/>
        <description>Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to the "initialization code for the hardware crypto accelerator."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-10-31T15:25:06.697-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:29.706-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:54.883-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco PIX meets CVE-2008-3817">
        <criterion comment="PIX vulnerable versions" test_ref="oval:org.mitre.oval:tst:9232"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5499" version="1" class="vulnerability">
      <metadata>
        <title>Cisco PIX and ASA IPv6 Denial of Service Vulnerability</title>
        <affected family="pixos">
          <platform>Cisco PIX</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3816"/>
        <description>Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2(4)9 and 7.2(4)10 allows remote attackers to cause a denial of service (device reload) via a crafted IPv6 packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-26T11:06:36.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-10-31T15:25:08.305-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:28.045-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:53.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Cisco PIX meets CVE-2008-3816">
        <criterion comment="PIX vulnerable versions" test_ref="oval:org.mitre.oval:tst:9229"/>
        <criterion comment="config contains: ipv6" test_ref="oval:org.mitre.oval:tst:9340"/>
        <criterion negate="true" comment="config contains: no ipv6" test_ref="oval:org.mitre.oval:tst:8419"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <version_test id="oval:org.mitre.oval:tst:9247" version="1" comment="PIX vulnerable versions" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:6667"/>
      <state state_ref="oval:org.mitre.oval:ste:4577"/>
    </version_test>
    <line_test id="oval:org.mitre.oval:tst:9139" version="1" comment="config contains: nt-auth-domain-controller" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:5702"/>
      <state state_ref="oval:org.mitre.oval:ste:4512"/>
    </line_test>
    <version_test id="oval:org.mitre.oval:tst:9232" version="1" comment="PIX vulnerable versions" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:6667"/>
      <state state_ref="oval:org.mitre.oval:ste:4531"/>
    </version_test>
    <line_test id="oval:org.mitre.oval:tst:9340" version="1" comment="config contains: ipv6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:5702"/>
      <state state_ref="oval:org.mitre.oval:ste:4240"/>
    </line_test>
    <version_test id="oval:org.mitre.oval:tst:9229" version="1" comment="PIX vulnerable versions" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:6667"/>
      <state state_ref="oval:org.mitre.oval:ste:4049"/>
    </version_test>
    <line_test id="oval:org.mitre.oval:tst:8419" version="1" comment="config contains: no ipv6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <object object_ref="oval:org.mitre.oval:obj:5702"/>
      <state state_ref="oval:org.mitre.oval:ste:4640"/>
    </line_test>
  </tests>
  <objects>
    <version_object id="oval:org.mitre.oval:obj:6667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos"/>
    <line_object id="oval:org.mitre.oval:obj:5702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <show_subcommand>show running-config</show_subcommand>
    </line_object>
  </objects>
  <states>
    <version_state id="oval:org.mitre.oval:ste:4577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <pix_release operation="pattern match">7\.0\([0-7]\)\d*|7\.0\(8\)[0-2]?$|7\.1\([0-1]\)\d*|7\.1\(2\)(\d?|[1-6]\d|7[0-7])$|7\.2\([0-3]\)\d*|7\.2\(4\)(\d?|1[0-5])$|8\.0\([0-3]\)\d*|8\.0\(4\)[0-5]?$|8\.1\(0\)\d*|8\.1\(1\)(\d?|1[0-2])$</pix_release>
    </version_state>
    <line_state id="oval:org.mitre.oval:ste:4512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <show_subcommand>show running-config</show_subcommand>
      <config_line operation="pattern match">^\s*nt-auth-domain-controller</config_line>
    </line_state>
    <version_state id="oval:org.mitre.oval:ste:4531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <pix_release operation="pattern match">8\.0\([0-3]\)|8\.1\([0-1]\)</pix_release>
    </version_state>
    <line_state id="oval:org.mitre.oval:ste:4240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <show_subcommand>show running-config</show_subcommand>
      <config_line operation="pattern match">ipv6</config_line>
    </line_state>
    <version_state id="oval:org.mitre.oval:ste:4049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <pix_release operation="pattern match">7\.2\([0-3]\)\d*|7\.2\(4\)(\d?|10)$</pix_release>
    </version_state>
    <line_state id="oval:org.mitre.oval:ste:4640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#pixos">
      <show_subcommand>show running-config</show_subcommand>
      <config_line operation="pattern match">no\s+ipv6</config_line>
    </line_state>
  </states>
</oval_definitions>