CVE Database
/

CVE-2009-4455

Back to search

CVE-2009-4455

Published: Dec 29, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restrictions and access unauthorized web sites via a crafted URL obfuscated with ROT13 and a certain encoding. NOTE: this issue was originally reported as a vulnerability related to lack of restrictions to URLs listed in the Cisco WebVPN bookmark component, but the vendor states that "The bookmark feature is not a security feature."

VendorProductVersions

n/a

n/a

affected
n/a

References

61132
vdb-entry
x_refsource_OSVDB
ADV-2009-3577
vdb-entry
x_refsource_VUPEN
1023368
vdb-entry
x_refsource_SECTRACK
37710
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now