CVE-2011-0348

Cisco IOS < 12.4(24)MD3/12.4(22)MDA5/12.4(24)MDA3 - Access Restriction Bypass via HTTP

Title source: llm
STIX 2.1

Description

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46022
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0229
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70720
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43052
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024992
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64936

Scores

EPSS 0.0226
EPSS Percentile 81.2%

Details

CWE
CWE-264
Status published
Products (7)
cisco/ios 12.4\(11\)md
cisco/ios 12.4\(15\)md
cisco/ios 12.4\(22\)md
cisco/ios 12.4\(22\)mda
cisco/ios 12.4\(24\)md
cisco/ios 12.4\(24\)md1
cisco/ios 12.4\(24\)mda
Published Jan 28, 2011
Tracked Since Feb 18, 2026