Lucene search

K
cve[email protected]CVE-2011-2667
HistoryJul 28, 2011 - 10:55 p.m.

CVE-2011-2667

2011-07-2822:55:02
CWE-119
web.nvd.nist.gov
29
2
ca gateway security
http
icihttp.exe
remote code execution
vulnerability
cve-2011-2667

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.166 Low

EPSS

Percentile

96.0%

Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.

Affected configurations

NVD
Node
broadcomtotal_defenseMatchr12
OR
cagateway_securityMatch8.1

Social References

More

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.166 Low

EPSS

Percentile

96.0%