CVE-2009-2863
published 2009-09-28CVE-2009-2863: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the…
PriorityP337high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
2.47%
82.8th percentile
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
Affected
137 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Authentication Proxy Vulnerability
vendor_cisco·2009-09-23·CVSS 7.1
CVE-2009-2863 [HIGH] CWE-399 Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS® Software configured with
Authentication Proxy for HTTP(S), Web Authentication or the consent feature,
contains a vulnerability that may allow an unauthenticated session to bypass
the authentication proxy server or bypass the consent webpage.
Cisco has released software updates that address this vulnerability.
There are no workarounds that mitigate this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-auth-proxy
Note: The September 23, 2009, Cisco IOS Security Advisory bundled
publication includes eleven Security Advisories. Ten of the advisories address
vulnerabilities in Cisco IOS Software, and one advisory addresses a
vulnerability
Cisco
Cisco IOS Software Authentication Proxy Vulnerability
vendor_cisco
CVE-2009-2863 Cisco IOS Software Authentication Proxy Vulnerability
CVE-2009-2863: Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS � Software configured with Authentication Proxy for HTTP(S), Web Authentication or the consent feature, contains a vulnerability that may allow an unauthenticated session to bypass the authentication proxy server or bypass the consent webpage. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsy15227, CSCsy15227
GHSA
GHSA-r2mm-qr53-2j54: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-2863 [HIGH] CWE-287 GHSA-r2mm-qr53-2j54: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/58340http://tools.cisco.com/security/center/viewAlert.x?alertId=18882http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8132.shtmlhttp://www.securityfocus.com/bid/36491http://www.securitytracker.com/id?1022935https://exchange.xforce.ibmcloud.com/vulnerabilities/53453http://osvdb.org/58340http://tools.cisco.com/security/center/viewAlert.x?alertId=18882http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8132.shtmlhttp://www.securityfocus.com/bid/36491http://www.securitytracker.com/id?1022935https://exchange.xforce.ibmcloud.com/vulnerabilities/53453
2009-09-28
Published