PT-2012-1682 · Cisco · Cisco Asa

Published

2012-05-02

·

Updated

2023-08-15

·

CVE-2011-3285

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliances (ASA) 5500 series devices versions 8.0 through 8.4
Description A CRLF injection issue exists in the /+CSCOE+/logon.html endpoint, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.
Recommendations For versions 8.0 through 8.4, update to a version that contains a fix for this issue.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2011-3285

Affected Products

Cisco Asa