Lucene search

K
cve[email protected]CVE-2011-0348
HistoryJan 28, 2011 - 10:00 p.m.

CVE-2011-0348

2011-01-2822:00:05
CWE-264
web.nvd.nist.gov
20
cisco
ios
security
vulnerability
cve-2011-0348
csctk35917
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.8%

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.

Affected configurations

NVD
Node
ciscoiosMatch12.4\(11\)md
OR
ciscoiosMatch12.4\(15\)md
OR
ciscoiosMatch12.4\(22\)md
OR
ciscoiosMatch12.4\(22\)mda
OR
ciscoiosMatch12.4\(24\)md
OR
ciscoiosMatch12.4\(24\)md1
OR
ciscoiosMatch12.4\(24\)mda
AND
ciscocontent_services_gateway_second_generation

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.8%