CVE-2011-0348
published 2011-01-28CVE-2011-0348: Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco…
PriorityP336medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.27%
81.2th percentile
Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | content_services_gateway | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Content Services Gateway Vulnerabilities
vendor_cisco·2011-01-26·CVSS 7.8
CVE-2011-0348 [HIGH] CWE-399 Cisco Content Services Gateway Vulnerabilities
Cisco Content Services Gateway Vulnerabilities
A service policy bypass vulnerability exists in the Cisco Content
Services Gateway - Second Generation (CSG2), which runs on the Cisco Service
and Application Module for IP (SAMI). Under certain configurations this
vulnerability could allow:
Customers to access sites that would normally match a billing policy
to be accessed without being charged to the end customer
Customers to access sites that would normally be denied based on
configured restriction policies
Additionally, Cisco IOS Software Release 12.4(24)MD1 on the Cisco CSG2
contains two vulnerabilities that can be exploited by a remote, unauthenticated
attacker to create a denial of service condition that prevents traffic from
passing through the CSG2. These vulnerabilities require on
Cisco
Cisco Content Services Gateway Vulnerabilities
vendor_cisco
CVE-2011-0348 Cisco Content Services Gateway Vulnerabilities
CVE-2011-0348: Cisco Content Services Gateway Vulnerabilities
A service policy bypass vulnerability exists in the Cisco Content Services Gateway - Second Generation (CSG2), which runs on the Cisco Service and Application Module for IP (SAMI). Under certain configurations this vulnerability could allow: Customers to access sites that would normally match a billing policy to be accessed without being charged to the end customer Customers to access sites that would normally be denied based on configured restriction policies Additionally, Cisco IOS Software Release 12.4(24)MD1 on the Cisco CSG2 contains two vulnerabilities that can be exploited by a remote, unauthenticated attacker to create a denial of service condition that prevents traffic from passing through the CSG2. These vulnerabilitie
GHSA
GHSA-2gwh-vr5q-hm52: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2011-0348 [MEDIUM] GHSA-2gwh-vr5q-hm52: Cisco IOS 12
Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/70720http://secunia.com/advisories/43052http://securitytracker.com/id?1024992http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtmlhttp://www.securityfocus.com/bid/46022http://www.vupen.com/english/advisories/2011/0229https://exchange.xforce.ibmcloud.com/vulnerabilities/64936http://osvdb.org/70720http://secunia.com/advisories/43052http://securitytracker.com/id?1024992http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtmlhttp://www.securityfocus.com/bid/46022http://www.vupen.com/english/advisories/2011/0229https://exchange.xforce.ibmcloud.com/vulnerabilities/64936
2011-01-28
Published