Vulnerability Name: | CVE-2009-4913 (CCN-60009) | ||||||||
Assigned: | 2010-06-24 | ||||||||
Published: | 2010-06-24 | ||||||||
Updated: | 2010-06-30 | ||||||||
Summary: | The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far side of the box," which might allow remote attackers to bypass intended access restrictions via IPv6 packets, aka Bug ID CSCso58622. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-4913 Source: CCN Type: Cisco ASA 5580 Series Release Notes April 6, 2009 Cisco ASA 5580 Release Notes Version 8.1(2) Source: CONFIRM Type: Patch http://www.cisco.com/en/US/docs/security/asa/asa81/release/notes/asarn812.html Source: CCN Type: OSVDB ID: 65893 Cisco Adaptive Security Appliances (ASA) IPv6 Packet IP Service Exposure Remote Access Restriction Bypass Source: XF Type: UNKNOWN ciscoasa-ipv6-security-bypass(60009) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |