CVE-2010-1576: Input Validation
The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1576?
CVE-2010-1576 has been classified with a medium to high severity rating due to potential remote code execution risks.
How do I fix CVE-2010-1576?
To mitigate CVE-2010-1576, upgrade the Cisco Content Services Switch 11500 to version 8.20.4.02 or later and the ACE 4710 to version A2(3.0) or later.
What versions of Cisco products are affected by CVE-2010-1576?
CVE-2010-1576 affects Cisco Content Services Switch 11500 with versions prior to 8.20.4.02 and ACE 4710 prior to A2(3.0).
What is the risk associated with CVE-2010-1576?
The risk associated with CVE-2010-1576 includes the potential for attackers to exploit the vulnerability for unauthorized actions on the affected devices.
How can I determine if I am vulnerable to CVE-2010-1576?
To determine vulnerability to CVE-2010-1576, check your version of the Cisco Content Services Switch 11500 or ACE 4710 against the known affected versions.