PT-2010-3247 · Cisco · Cisco Content Services Switch (Css) 11500+1
Published
2010-07-06
·
Updated
2018-10-10
·
CVE-2010-1576
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Content Services Switch (CSS) 11500 versions prior to 8.20.4.02
Cisco Application Control Engine (ACE) 4710 versions prior to A2(3.0)
Description
The issue arises from improper handling of line feed (LF), carriage return (CR), and LFCR as alternatives to the standard CRLF sequence between HTTP headers. This allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data. For example, using LF characters before
ClientCert-Subject and ClientCert-Subject-CN headers.Recommendations
For Cisco Content Services Switch (CSS) 11500 versions prior to 8.20.4.02, update to version 8.20.4.02 or later.
For Cisco Application Control Engine (ACE) 4710 versions prior to A2(3.0), update to version A2(3.0) or later.
As a temporary workaround, consider restricting the use of LF, CR, and LFCR characters in HTTP headers to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Application Control Engine (Ace) 4710
Cisco Content Services Switch (Css) 11500