CVE Database
/

CVE-2010-1576

Back to search

CVE-2010-1576

Published: Jul 6, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.

VendorProductVersions

n/a

n/a

affected
n/a

References

1024167
vdb-entry
x_refsource_SECTRACK
41315
vdb-entry
x_refsource_BID
66092
vdb-entry
x_refsource_OSVDB
1024168
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now