First published: Tue Jun 29 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASA 5580 | <=8.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4910 has a medium severity rating due to its potential for remote exploitation via cross-site scripting.
To mitigate CVE-2009-4910, upgrade the Cisco Adaptive Security Appliance software to version 8.1(2) or later.
CVE-2009-4910 affects Cisco Adaptive Security Appliance 5580 series devices running software versions prior to 8.1(2).
CVE-2009-4910 allows remote attackers to perform cross-site scripting attacks, injecting arbitrary web scripts into the WebVPN portal.
There are no official workarounds for CVE-2009-4910; upgrading to a patched version is the recommended solution.