CVE-2009-4455
Cisco ASA 5500 Series 7.0-8.2 - Authenticated Access Restriction Bypass via Obfuscated URL
Title source: llmDescription
The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restrictions and access unauthorized web sites via a crafted URL obfuscated with ROT13 and a certain encoding. NOTE: this issue was originally reported as a vulnerability related to lack of restrictions to URLs listed in the Cisco WebVPN bookmark component, but the vendor states that "The bookmark feature is not a security feature."
References (6)
Core 6
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3577
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508530/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/61132
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1023368
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/37710
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=19609
Scores
EPSS
0.0131
EPSS Percentile
67.6%
Details
CWE
CWE-264
Status
published
Products (6)
cisco/adaptive_security_appliance_5500
7.0
cisco/adaptive_security_appliance_5500
7.1
cisco/adaptive_security_appliance_5500
7.2
cisco/adaptive_security_appliance_5500
8.0
cisco/adaptive_security_appliance_5500
8.1
cisco/adaptive_security_appliance_5500
8.2
Published
Dec 29, 2009
Tracked Since
Feb 18, 2026