First published: Thu May 03 2012(Updated: )
CRLF injection vulnerability in autologin.jsp in Cisco CiscoWorks Common Services 4.0, as used in Cisco Prime LAN Management Solution and other products, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter, aka Bug ID CSCtu18693.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime LAN Management Solution | =4.2 | |
Cisco CiscoWorks Common Services | =4.0 | |
Cisco Prime LAN Management Solution | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4237 is classified as a high severity vulnerability due to its potential for remote exploitation via CRLF injection.
To mitigate CVE-2011-4237, update the affected Cisco products to the latest patched versions as advised by Cisco.
CVE-2011-4237 affects CiscoWorks Common Services 4.0 and Cisco Prime LAN Management Solution 4.2.
CVE-2011-4237 can facilitate HTTP response splitting attacks through the injection of arbitrary HTTP headers.
CVE-2011-4237 was disclosed in 2011 as a vulnerability impacting specific Cisco network management solutions.