CVE-2011-3285: Code Injection
CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCth63101.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3285?
CVE-2011-3285 is classified as a high severity vulnerability due to its potential to allow remote attackers to inject arbitrary HTTP headers.
How do I fix CVE-2011-3285?
To remediate CVE-2011-3285, update your Cisco Adaptive Security Appliance to a patched software version recommended by Cisco.
What devices are affected by CVE-2011-3285?
CVE-2011-3285 affects Cisco Adaptive Security Appliances (ASA) 5500 series devices running software versions 8.0 through 8.4.
What kind of attacks can CVE-2011-3285 allow?
CVE-2011-3285 can enable attackers to conduct HTTP response splitting attacks.
Is there a workaround for CVE-2011-3285?
There are no documented workarounds for CVE-2011-3285; the recommended solution is to apply the appropriate software patch.