First published: Mon Aug 12 2002(Updated: )
The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Content Distribution Manager 4650 | =4.1 | |
Cisco Cache Engine 505 | =2.4.0 | |
Cisco Content Engine | =507_4.0 | |
Cisco Content Engine | =590_2.2.0 | |
Cisco Content Distribution Manager 4650 | =4.0 | |
Cisco Content Engine | =7320_4.0 | |
Cisco Content Engine | =7320_2.2.0 | |
Cisco Content Distribution Manager 4630 | =4.1 | |
Cisco Content Engine | =507_4.1 | |
Cisco Cache Engine 550 | ||
Cisco Cache Engine 505 | =3.0 | |
Cisco Content Engine | =7320 | |
Cisco Cache Engine 570 | =2.4.0 | |
Cisco Content Engine | =507_3.1 | |
Cisco Content Distribution Manager 4630 | =4.0 | |
Cisco Content Engine | =560_4.0 | |
Cisco Content Engine | =590_4.0 | |
Cisco Content Engine | =560_4.1 | |
Cisco Content Distribution Manager 4650 | ||
Cisco Content Distribution Manager 4630 | ||
Cisco Content Engine | =590_3.1 | |
Cisco Cache Engine 570 | =2.2.0 | |
Cisco Cache Engine 570 | =570 | |
Cisco Content Router 4430 | ||
Cisco Content Engine | =560 | |
Cisco Content Engine | =507 | |
Cisco Content Engine | =590 | |
Cisco Content Engine | =507_2.2.0 | |
Cisco Cache Engine 570 | =3.0 | |
Cisco Content Engine | =560_3.1 | |
Cisco Content Engine | =590_4.1 | |
Cisco Cache Engine 550 | =2.4.0 | |
Cisco Content Engine | =7320_3.1 | |
Cisco Content Engine | =560_2.2.0 | |
Cisco Content Engine | =7320_4.1 | |
Cisco Cache Engine 550 | =3.0 | |
Cisco Cache Engine 550 | =2.2.0 | |
Cisco Enterprise Content Delivery Network Software | =4.0 | |
Cisco Enterprise Content Delivery Network Software | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0778 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2002-0778, you should update the affected Cisco devices to the latest firmware or specific patched versions provided by Cisco.
CVE-2002-0778 affects specific versions of Cisco Cache Engine and Content Engine products, including multiple versions of the Content Distribution Manager.
The impact of CVE-2002-0778 allows remote attackers to bypass access controls and establish TCP connections while concealing their true IP addresses.
While CVE-2002-0778 has been acknowledged as a serious vulnerability, there is limited information available on whether it is actively being exploited in the wild.