CVE-2009-1202
published 2009-06-25CVE-2009-1202: WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.98%
78.4th percentile
WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9634-hx95-7px5: WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8
ghsa_unreviewed·2022-05-02
CVE-2009-1202 [MEDIUM] CWE-79 GHSA-9634-hx95-7px5: WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8
WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.
Cisco
Cisco ASA Adaptive Security Appliance Software Clientless SSL VPN Rot13-Encoded Cross-Site Scripting Vulnerability
vendor_cisco·2009-06-24·CVSS 4.3
CVE-2009-1202 [MEDIUM] Cisco ASA Adaptive Security Appliance Software Clientless SSL VPN Rot13-Encoded Cross-Site Scripting Vulnerability
Cisco ASA Adaptive Security Appliance Software Clientless SSL VPN Rot13-Encoded Cross-Site Scripting Vulnerability
Cisco ASA Adaptive Security Appliance Software versions prior to 8.0.4(34), 8.1.2(25), and 8.2.1(3) that have been configured to accept Clientless SSL VPN connections contain a cross-site scripting vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary script or HTML code in a user's browser session. Versions 7.x are not affected.
The vulnerability is due to insufficient restrictions on Rot13-encoded URL parameters that are utilized by the SSL VPN feature of Cisco ASA Software when clients browse web pages by means of the VPN web portal. An attacker who could convince a user to visit a malicious page while logged into the secure portal could e
Suricata
ET WEB_SERVER Possible Cisco ASA Appliance Clientless SSL VPN HTML Rewriting Security Bypass Attempt/Cross Site Scripting Attempt
suricata·2010-07-30
CVE-2009-1201 ET WEB_SERVER Possible Cisco ASA Appliance Clientless SSL VPN HTML Rewriting Security Bypass Attempt/Cross Site Scripting Attempt
ET WEB_SERVER Possible Cisco ASA Appliance Clientless SSL VPN HTML Rewriting Security Bypass Attempt/Cross Site Scripting Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER Possible Cisco ASA Appliance Clientless SSL VPN HTML Rewriting Security Bypass Attempt/Cross Site Scripting Attempt"; flow:established,to_client; file.data; content:"CSCO_WebVPN"; fast_pattern; nocase; content:"csco_wrap_js"; within:100; nocase; reference:url,tools.cisco.com/security/center/viewAlert.x?alertId=18442; reference:url,www.securityfocus.com/archive/1/504516; reference:url,www.securityfocus.com/bid/35476; reference:cve,2009-1201; reference:cve,2009-1202; classtype:web-application-attack; sid:2010730; rev:6; metadata:affected_product Web_Server_Applications, attack_target Web_Serv
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/35511http://www.securityfocus.com/archive/1/504516/100/0/threadedhttp://www.securityfocus.com/bid/35480http://www.securitytracker.com/id?1022457http://www.vupen.com/english/advisories/2009/1713http://secunia.com/advisories/35511http://www.securityfocus.com/archive/1/504516/100/0/threadedhttp://www.securityfocus.com/bid/35480http://www.securitytracker.com/id?1022457http://www.vupen.com/english/advisories/2009/1713
2009-06-25
Published