CVE-2010-1575: High severity cisco content services switch 11500 vulnerability
The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert- headers but does not delete client-supplied ClientCert- headers, which might allow remote attackers to bypass authentication via crafted header data, as demonstrated by a ClientCert-Subject-CN header, aka Bug ID CSCsz04690.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1575?
CVE-2010-1575 is considered a high-severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2010-1575?
To fix CVE-2010-1575, it is recommended to upgrade the Cisco Content Services Switch to a patched version that addresses this vulnerability.
What kind of attacks can exploit CVE-2010-1575?
CVE-2010-1575 can be exploited through crafted headers that bypass the authentication mechanism.
Which Cisco devices are affected by CVE-2010-1575?
CVE-2010-1575 specifically affects the Cisco Content Services Switch 11500 running software version 08.20.1.01.
What does CVE-2010-1575 involve regarding headers?
CVE-2010-1575 involves the retention of client-supplied ClientCert-* headers, allowing attackers to manipulate authentication data.