CVE-2012-0334Improper Input Validation in Cisco Ironport WEB Security Appliance

Severity
6.4MEDIUMNVD
EPSS
0.1%
top 80.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateApr 23

Description

Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-vwvh-jw4m-wvv2: Cisco IronPort Web Security Appliance AsyncOS software prior to 72022-04-23
CVEList
CVE-2012-0334: Cisco IronPort Web Security Appliance AsyncOS software prior to 72020-01-15

📋Vendor Advisories

1
Cisco
Cisco IronPort Web Security Appliance AsyncOS SSL Certificate Caching Vulnerability2012-04-12
CVE-2012-0334 — Improper Input Validation in Cisco | cvebase