First published: Thu Jun 25 2009(Updated: )
Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.0\(4\) | |
Cisco Adaptive Security Appliance Software | =8.1.2 | |
Cisco Adaptive Security Appliance Software | =8.2.1 | |
Cisco Adaptive Security Appliance Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1201 has been classified with a medium severity rating due to its potential for cross-site scripting attacks.
To mitigate CVE-2009-1201, update the Cisco Adaptive Security Appliance software to a version that is not susceptible to this vulnerability.
CVE-2009-1201 affects Cisco Adaptive Security Appliances running software versions 8.0(4), 8.1.2, and 8.2.1.
The impact of CVE-2009-1201 includes the potential for remote attackers to execute cross-site scripting attacks.
Yes, CVE-2009-1201 can be exploited remotely, allowing attackers to bypass security mechanisms.