CVE-2009-2863
published 2009-09-28CVE-2009-2863: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the…
high7.1CVSS 3.1
AVNACMAuNCCINAN
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
Affected
137 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Cisco
Cisco IOS Software Authentication Proxy Vulnerability
vendor_cisco·2009-09-23·CVSS 7.1
CVE-2009-2863 [HIGH] CWE-399 Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS® Software configured with
Authentication Proxy for HTTP(S), Web Authentication or the consent feature,
contains a vulnerability that may allow an unauthenticated session to bypass
the authentication proxy server or bypass the consent webpage.
Cisco has released software updates that address this vulnerability.
There are no workarounds that mitigate this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-auth-proxy
Note: The September 23, 2009, Cisco IOS Security Advisory bundled
publication includes eleven Security Advisories. Ten of the advisories address
vulnerabilities in Cisco IOS Software, and one advisory addresses a
vulnerability
Cisco
Cisco IOS Software Authentication Proxy Vulnerability
vendor_cisco
CVE-2009-2863 Cisco IOS Software Authentication Proxy Vulnerability
CVE-2009-2863: Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS � Software configured with Authentication Proxy for HTTP(S), Web Authentication or the consent feature, contains a vulnerability that may allow an unauthenticated session to bypass the authentication proxy server or bypass the consent webpage. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsy15227, CSCsy15227
GHSA
GHSA-r2mm-qr53-2j54: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-2863 [HIGH] CWE-287 GHSA-r2mm-qr53-2j54: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/58340http://tools.cisco.com/security/center/viewAlert.x?alertId=18882http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8132.shtmlhttp://www.securityfocus.com/bid/36491http://www.securitytracker.com/id?1022935https://exchange.xforce.ibmcloud.com/vulnerabilities/53453http://osvdb.org/58340http://tools.cisco.com/security/center/viewAlert.x?alertId=18882http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8132.shtmlhttp://www.securityfocus.com/bid/36491http://www.securitytracker.com/id?1022935https://exchange.xforce.ibmcloud.com/vulnerabilities/53453
2009-09-28
Published