CVE Database
/

CVE-2010-2629

Back to search

CVE-2010-2629

Published: Jul 6, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1576.

VendorProductVersions

n/a

n/a

affected
n/a

References

1024167
vdb-entry
x_refsource_SECTRACK
41315
vdb-entry
x_refsource_BID
1024168
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now