CVE-2009-4912Cisco ASA 5580 vulnerability

CWE-2643 documents3 sources
Severity
10.0CRITICALNVD
EPSS
0.3%
top 46.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 29
Latest updateMay 2

Description

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDcisco/asa_55808.1\(1\)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wv8r-qj2j-7h4m: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 82022-05-02
CVEList
CVE-2009-4912: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 82010-06-29
CVE-2009-4912 — Cisco ASA 5580 vulnerability | cvebase