2024-12-08 03:06:42 +00:00

91 lines
2.8 KiB
JSON

{
"id": "CVE-2009-4912",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-06-29T18:30:01.507",
"lastModified": "2024-11-21T01:10:45.603",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876."
},
{
"lang": "es",
"value": "Dispositivos Cisco Adaptive Security Appliances (ASA) de la serie 5580 con versi\u00f3n de software anterior a v8.1(2) completan un \"handshake\" (establacimiento de conexi\u00f3n) SSL con un cliente HTTPS incluso si dicho cliente no est\u00e1 autorizado, lo que podr\u00eda permitir a atacantes remotos evitar resctricciones de acceso establacidas a trav\u00e9s de una sesi\u00f3n HTTPS, tambi\u00e9n conocido como Bug ID CSCso10876."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 10.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:h:cisco:asa_5580:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.1\\(1\\)",
"matchCriteriaId": "73E464BF-EEFB-4D23-9F86-B41B4850223E"
}
]
}
]
}
],
"references": [
{
"url": "http://www.cisco.com/en/US/docs/security/asa/asa81/release/notes/asarn812.html",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.cisco.com/en/US/docs/security/asa/asa81/release/notes/asarn812.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
}
]
}