First published: Thu Jun 25 2009(Updated: )
WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.0\(4\) | |
Cisco Adaptive Security Appliance Software | =8.1.2 | |
Cisco Adaptive Security Appliance Software | =8.2.1 | |
Cisco Adaptive Security Appliance Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1202 has a medium severity level, posing a risk of cross-site scripting (XSS) attacks.
To fix CVE-2009-1202, upgrade your Cisco Adaptive Security Appliance Software to a version later than 8.2.1.
CVE-2009-1202 affects Cisco Adaptive Security Appliance devices running software versions 8.0(4), 8.1.2, and 8.2.1.
Yes, CVE-2009-1202 can be exploited remotely, allowing attackers to bypass security mechanisms.
The consequences of CVE-2009-1202 include potential unauthorized access and cross-site scripting attacks on vulnerable systems.