Lucene search

K
cveCiscoCVE-2014-2137
HistoryApr 02, 2014 - 3:58 a.m.

CVE-2014-2137

2014-04-0203:58:17
CWE-20
cisco
web.nvd.nist.gov
23
cisco
web security appliance
wsa
vulnerability
crlf injection
redirection attacks
cve-2014-2137
bug id cscuj61002

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

50.6%

CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.

Affected configurations

Nvd
Node
ciscoweb_security_virtual_applianceRange7.7
OR
ciscoweb_security_virtual_applianceMatch7.1.0
OR
ciscoweb_security_virtual_applianceMatch7.1.1
OR
ciscoweb_security_virtual_applianceMatch7.1.2
OR
ciscoweb_security_virtual_applianceMatch7.1.3
OR
ciscoweb_security_virtual_applianceMatch7.1.4
OR
ciscoweb_security_virtual_applianceMatch7.5.0
OR
ciscoweb_security_virtual_applianceMatch7.5.1
OR
ciscoweb_security_applianceMatch-
VendorProductVersionCPE
ciscoweb_security_virtual_appliance*cpe:2.3:a:cisco:web_security_virtual_appliance:*:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.1.0cpe:2.3:a:cisco:web_security_virtual_appliance:7.1.0:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.1.1cpe:2.3:a:cisco:web_security_virtual_appliance:7.1.1:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.1.2cpe:2.3:a:cisco:web_security_virtual_appliance:7.1.2:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.1.3cpe:2.3:a:cisco:web_security_virtual_appliance:7.1.3:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.1.4cpe:2.3:a:cisco:web_security_virtual_appliance:7.1.4:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.5.0cpe:2.3:a:cisco:web_security_virtual_appliance:7.5.0:*:*:*:*:*:*:*
ciscoweb_security_virtual_appliance7.5.1cpe:2.3:a:cisco:web_security_virtual_appliance:7.5.1:*:*:*:*:*:*:*
ciscoweb_security_appliance-cpe:2.3:h:cisco:web_security_appliance:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

50.6%

Related for CVE-2014-2137