Lucene search

K
cveMitreCVE-2009-1203
HistoryJun 25, 2009 - 5:30 p.m.

CVE-2009-1203

2009-06-2517:30:00
mitre
web.nvd.nist.gov
30
cve-2009-1203
webvpn
cisco asa
remote attack
credentials
url
bug id cscsy80709
nvd

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.037

Percentile

91.9%

WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.

Affected configurations

Nvd
Node
ciscoadaptive_security_applianceMatch8.0\(4\)
OR
ciscoadaptive_security_applianceMatch8.1.2
OR
ciscoadaptive_security_applianceMatch8.2.1
AND
ciscoadaptive_security_appliance
VendorProductVersionCPE
ciscoadaptive_security_appliance8.0(4)cpe:2.3:a:cisco:adaptive_security_appliance:8.0\(4\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance8.1.2cpe:2.3:a:cisco:adaptive_security_appliance:8.1.2:*:*:*:*:*:*:*
ciscoadaptive_security_appliance8.2.1cpe:2.3:a:cisco:adaptive_security_appliance:8.2.1:*:*:*:*:*:*:*
ciscoadaptive_security_appliance*cpe:2.3:h:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.037

Percentile

91.9%