Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1201Cross-site Scripting in Cisco Adaptive Security Appliance

CWE-79Cross-site Scripting12 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
4.9%
top 10.44%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 25
Latest updateMay 2

Description

Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDcisco/adaptive_security_appliance8.0\(4\), 8.1.2, 8.2.1+2

🔴Vulnerability Details

2
GHSA
GHSA-6wmj-w48w-cqh5: Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte2022-05-02
CVEList
CVE-2009-1201: Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte2009-06-25

💥Exploits & PoCs

1
Exploit-DB
Cisco ASA Appliance 8.x - WebVPN DOM Wrapper Cross-Site Scripting2009-05-24

🔍Detection Rules

1
Suricata
ET WEB_SERVER Possible Cisco ASA Appliance Clientless SSL VPN HTML Rewriting Security Bypass Attempt/Cross Site Scripting Attempt2010-07-30

📋Vendor Advisories

1
Cisco
Cisco ASA Adaptive Security Appliance Clientless SSL VPN DOM Cross-Site Scripting Vulnerability2009-06-24

💬Community

5
Bugzilla
CVE-2009-2690 OpenJDK private variable information disclosure (6777487)2009-07-22
Bugzilla
CVE-2009-2476 OpenJDK OpenType checks can be bypassed (6736293)2009-07-22
Bugzilla
CVE-2009-2689 OpenJDK JDK13Services grants unnecessary privileges (6777448)2009-07-22
Bugzilla
CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)2009-07-21
Bugzilla
CVE-2009-2674 Java Web Start Buffer JPEG processing integer overflow (6823373)2009-07-21
CVE-2009-1201 — Cross-site Scripting in Cisco | cvebase