PT-2009-5221 · Cisco · Cisco Ios

Published

2009-09-23

·

Updated

2017-08-17

·

CVE-2009-2863

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.0 through 12.4
Description A race condition in the Firewall Authentication Proxy feature allows remote attackers to bypass authentication or the consent web page via a crafted request. This issue affects Cisco IOS Software configured with Authentication Proxy for HTTP(S), Web Authentication, or the consent feature, potentially allowing an unauthenticated session to bypass the authentication proxy server or consent webpage.
Recommendations For Cisco IOS versions 12.0 through 12.4, update to a version that addresses this vulnerability, as Cisco has released software updates that fix this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability, but it is known that Cisco has released updates.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2863

Affected Products

Cisco Ios