Lucene search

K
cveCiscoCVE-2009-1160
HistoryApr 09, 2009 - 3:08 p.m.

CVE-2009-1160

2009-04-0915:08:35
CWE-264
cisco
web.nvd.nist.gov
29
cisco
asa
pix
5500 series
security appliances
access restrictions
vulnerability
bug
cscsq91277
cve-2009-1160

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.004

Percentile

72.4%

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access restrictions, aka Bug ID CSCsq91277.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_5500Match7.0
OR
ciscoadaptive_security_appliance_5500Match7.1
OR
ciscoadaptive_security_appliance_5500Match7.2
OR
ciscoadaptive_security_appliance_5500Match8.0
OR
ciscoadaptive_security_appliance_5500Match8.1
OR
ciscopixMatch7.0
OR
ciscopixMatch7.1
OR
ciscopixMatch7.2
OR
ciscopixMatch8.0
VendorProductVersionCPE
ciscoadaptive_security_appliance_55007.0cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.0:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55007.1cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.1:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55007.2cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.2:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55008.0cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.0:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55008.1cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.1:*:*:*:*:*:*:*
ciscopix7.0cpe:2.3:h:cisco:pix:7.0:*:*:*:*:*:*:*
ciscopix7.1cpe:2.3:h:cisco:pix:7.1:*:*:*:*:*:*:*
ciscopix7.2cpe:2.3:h:cisco:pix:7.2:*:*:*:*:*:*:*
ciscopix8.0cpe:2.3:h:cisco:pix:8.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.004

Percentile

72.4%