CVE-2002-0778

Severity
7.5HIGH
EPSS
0.8%
top 25.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateApr 30

Description

The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages7 packages

NVDcisco/content_engine20 versions+19
NVDcisco/cache_engine_5052.4.0, 3.0+1
NVDcisco/cache_engine_5502.2.0, 2.4.0, 3.0+2
NVDcisco/cache_engine_5704 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x9q3-xj96-chmv: The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allow2022-04-30
CVEList
CVE-2002-0778: The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allow2003-04-02

📋Vendor Advisories

1
Cisco
Transparent Cache Engine and Content Engine TCP Relay Vulnerability2002-05-15
CVE-2002-0778 (HIGH CVSS 7.5) | The default configuration of the pr | cvebase.io