PT-2009-6576 · Cisco · Cisco Asa

Publicado

2009-12-29

·

Atualizado

2018-10-10

·

CVE-2009-4455

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco ASA versions 7.0 through 8.2
Description The default configuration of Cisco ASA allows portal traffic to access arbitrary backend servers. This might allow remote authenticated users to bypass intended access restrictions and access unauthorized web sites via a crafted URL. The issue was initially reported in relation to the Cisco WebVPN bookmark component, but the vendor clarified that the bookmark feature is not a security feature.
Recommendations For Cisco ASA versions 7.0 through 8.2, consider restricting access to arbitrary backend servers to minimize the risk of exploitation. As a temporary workaround, limit the URLs that can be accessed through the portal traffic. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4455

Produtos afetados

Cisco Asa