CVE-2009-4455

Cisco ASA 5500 Series 7.0-8.2 - Authenticated Access Restriction Bypass via Obfuscated URL

Title source: llm
STIX 2.1

Description

The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restrictions and access unauthorized web sites via a crafted URL obfuscated with ROT13 and a certain encoding. NOTE: this issue was originally reported as a vulnerability related to lack of restrictions to URLs listed in the Cisco WebVPN bookmark component, but the vendor states that "The bookmark feature is not a security feature."

References (6)

Core 6
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3577
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508530/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/61132
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1023368
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37710

Scores

EPSS 0.0131
EPSS Percentile 67.6%

Details

CWE
CWE-264
Status published
Products (6)
cisco/adaptive_security_appliance_5500 7.0
cisco/adaptive_security_appliance_5500 7.1
cisco/adaptive_security_appliance_5500 7.2
cisco/adaptive_security_appliance_5500 8.0
cisco/adaptive_security_appliance_5500 8.1
cisco/adaptive_security_appliance_5500 8.2
Published Dec 29, 2009
Tracked Since Feb 18, 2026