CVE-2012-0335
published 2012-05-02CVE-2012-0335: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.23%
80.8th percentile
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat6.0MEDIUM
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
ghsa·2022-05-05
CVE-2013-0335 [HIGH] CWE-863 OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
GHSA
GHSA-mxfj-4qf9-32fh: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7
ghsa_unreviewed·2022-05-04
CVE-2012-0335 [MEDIUM] CWE-287 GHSA-mxfj-4qf9-32fh: Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.
Red Hat
CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
vendor_redhat·2013-03-22·CVSS 6.0
CVE-2013-0335 [MEDIUM] CWE-613 CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: redhat-user-workloads/openstack-nova-compute (Red Hat OpenStack Platform
Cisco
Cisco ASA 5500 Series Adaptive Security Appliance Cut-Through Proxy Authentication Information Disclosure Vulnerability
vendor_cisco·2012-05-16·CVSS 5.0
CVE-2012-0335 [MEDIUM] CWE-200 Cisco ASA 5500 Series Adaptive Security Appliance Cut-Through Proxy Authentication Information Disclosure Vulnerability
Cisco ASA 5500 Series Adaptive Security Appliance Cut-Through Proxy Authentication Information Disclosure Vulnerability
Cisco ASA 5500 Series Adaptive Security Appliance firmware contains a vulnerability that could allow an unauthenticated, remote attacker to access sensitive information on a targeted system.
The vulnerability is due to improper proxy authentication during attempts to cut through a targeted system. An unauthenticated, remote attacker could exploit this vulnerability to access sensitive information by tricking a user into authenticating to the system. If successful, the attacker could use this information to launch further attacks.
Cisco has confirmed this vulnerability and released software updates.
To exploit this vulnerability, an attacker would need to access trusted
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/49139http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.htmlhttp://www.securityfocus.com/bid/53558http://www.securitytracker.com/id?1027008http://secunia.com/advisories/49139http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.htmlhttp://www.securityfocus.com/bid/53558http://www.securitytracker.com/id?1027008
2012-05-02
Published