cbcvebase.
CVE-2009-1160
published 2009-04-09

CVE-2009-1160: Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before…

PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.14%
63.0th percentile
Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access restrictions, aka Bug ID CSCsq91277.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_5500
ciscoadaptive_security_appliance_5500
ciscoadaptive_security_appliance_5500
ciscoadaptive_security_appliance_5500
ciscoadaptive_security_appliance_5500
ciscoasa_adaptive_security_appliance_and_cisco_pix_security_appliances
ciscopix
ciscopix
ciscopix
ciscopix

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.