Lucene search

K
nvd[email protected]NVD:CVE-2009-1203
HistoryJun 25, 2009 - 5:30 p.m.

CVE-2009-1203

2009-06-2517:30:00
web.nvd.nist.gov
6

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%

WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.

Affected configurations

Nvd
Node
ciscoadaptive_security_applianceMatch8.0\(4\)
OR
ciscoadaptive_security_applianceMatch8.1.2
OR
ciscoadaptive_security_applianceMatch8.2.1
AND
ciscoadaptive_security_appliance
VendorProductVersionCPE
ciscoadaptive_security_appliance8.0(4)cpe:2.3:a:cisco:adaptive_security_appliance:8.0\(4\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance8.1.2cpe:2.3:a:cisco:adaptive_security_appliance:8.1.2:*:*:*:*:*:*:*
ciscoadaptive_security_appliance8.2.1cpe:2.3:a:cisco:adaptive_security_appliance:8.2.1:*:*:*:*:*:*:*
ciscoadaptive_security_appliance*cpe:2.3:h:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.037

Percentile

91.9%