CVE-2011-0348
Cisco IOS < 12.4(24)MD3/12.4(22)MDA5/12.4(24)MDA3 - Access Restriction Bypass via HTTP
Title source: llmDescription
Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46022
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0229
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/70720
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43052
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1024992
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64936
Scores
EPSS
0.0226
EPSS Percentile
81.2%
Details
CWE
CWE-264
Status
published
Products (7)
cisco/ios
12.4\(11\)md
cisco/ios
12.4\(15\)md
cisco/ios
12.4\(22\)md
cisco/ios
12.4\(22\)mda
cisco/ios
12.4\(24\)md
cisco/ios
12.4\(24\)md1
cisco/ios
12.4\(24\)mda
Published
Jan 28, 2011
Tracked Since
Feb 18, 2026