Vulnerability CVE-2009-3457


Published: 2009-09-29   Modified: 2012-02-13

Description:
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Cisco ACE XML Gateway <= 6.0 Internal IP disclosure
Alejandro Hernan...
01.10.2009

Type:

CWE-200

(Information Exposure)

Vendor: Cisco
Product: Ace xml gateway 
Version:
6.0(3)
6.0(2)
6.0(1)
6.0(0)
Product: Ace web application firewall 
Version:
6.0(3)
6.0(2)
6.0(1)
6.0(0)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://seclists.org/fulldisclosure/2009/Sep/0369.html
http://www.brainoverflow.org/advisories/cisco_ace_xml_gw_ip_disclosure.txt
http://www.cisco.com/en/US/products/products_security_response09186a0080af8965.html
http://www.securityfocus.com/archive/1/506716/100/0/threaded
http://www.securityfocus.com/bid/36522
http://www.securitytracker.com/id?1022949
http://www.vupen.com/english/advisories/2009/2778
https://exchange.xforce.ibmcloud.com/vulnerabilities/53482

Related CVE
CVE-2019-1841
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-s...
CVE-2019-1840
A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerability is due...
CVE-2019-1837
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to i...
CVE-2019-1835
A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI com...
CVE-2019-1834
A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is con...
CVE-2019-1831
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper ...
CVE-2019-1830
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) conditio...
CVE-2019-1829
A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administ...

Copyright 2019, cxsecurity.com

 

Back to Top