First published: Tue Aug 20 2002(Updated: )
The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebNS | ||
Cisco Content Services Switch 11000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0870 is categorized as a high severity vulnerability due to its authentication bypass nature.
To mitigate CVE-2002-0870, ensure you have applied the latest patches from Cisco for the Content Services Switch 11000 Series.
CVE-2002-0870 affects the Cisco Content Services Switch 11000 and Cisco WebNS software.
An attacker can exploit CVE-2002-0870 to gain unauthorized access to management functions of the affected devices.
CVE-2002-0870 is not rare, as it involves a common issue with authentication bypass found in several Cisco products.