CVE-2009-4910: XSS
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4910?
CVE-2009-4910 has a medium severity rating due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2009-4910?
To mitigate CVE-2009-4910, upgrade the Cisco Adaptive Security Appliance software to version 8.1(2) or later.
What devices are affected by CVE-2009-4910?
CVE-2009-4910 affects Cisco Adaptive Security Appliance 5580 series devices running software versions prior to 8.1(2).
What kind of attack is possible with CVE-2009-4910?
CVE-2009-4910 allows remote attackers to perform cross-site scripting attacks, injecting arbitrary web scripts into the WebVPN portal.
Are there any workarounds for CVE-2009-4910?
There are no official workarounds for CVE-2009-4910; upgrading to a patched version is the recommended solution.