CVE-2009-2119: XSS
Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2119?
CVE-2009-2119 has a moderate severity rating due to its potential for cross-site scripting attacks that can compromise user sessions.
How do I fix CVE-2009-2119?
To fix CVE-2009-2119, upgrade F5 FirePass SSL VPN to a version that patches this XSS vulnerability, specifically versions after 6.0.3.
Who is affected by CVE-2009-2119?
CVE-2009-2119 affects users of F5 FirePass SSL VPN versions 5.5 to 6.0.3.
What type of vulnerability is CVE-2009-2119?
CVE-2009-2119 is a cross-site scripting (XSS) vulnerability allowing attackers to inject malicious scripts.
Can CVE-2009-2119 be exploited remotely?
Yes, CVE-2009-2119 can be exploited remotely by attackers to inject arbitrary web scripts via the login interface.