CVE-2009-4912
Cisco ASA 5580 < 8.1(2) - Unauthenticated SSL Handshake Bypass via HTTPS Session
Title source: llmDescription
Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876.
References (1)
Core 1
Core References
Patch x_refsource_confirm
http://www.cisco.com/en/US/docs/security/asa/asa81/release/notes/asarn812.html
Scores
EPSS
0.0252
EPSS Percentile
83.2%
Details
CWE
CWE-264
Status
published
Products (1)
cisco/asa_5580
< 8.1\(1\)
Published
Jun 29, 2010
Tracked Since
Feb 18, 2026