PT-2010-3247 · Cisco · Cisco Content Services Switch (Css) 11500+1

Published

2010-07-06

·

Updated

2018-10-10

·

CVE-2010-1576

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Content Services Switch (CSS) 11500 versions prior to 8.20.4.02 Cisco Application Control Engine (ACE) 4710 versions prior to A2(3.0)
Description The issue arises from improper handling of line feed (LF), carriage return (CR), and LFCR as alternatives to the standard CRLF sequence between HTTP headers. This allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data. For example, using LF characters before ClientCert-Subject and ClientCert-Subject-CN headers.
Recommendations For Cisco Content Services Switch (CSS) 11500 versions prior to 8.20.4.02, update to version 8.20.4.02 or later. For Cisco Application Control Engine (ACE) 4710 versions prior to A2(3.0), update to version A2(3.0) or later. As a temporary workaround, consider restricting the use of LF, CR, and LFCR characters in HTTP headers to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1576

Affected Products

Cisco Application Control Engine (Ace) 4710
Cisco Content Services Switch (Css) 11500