HIGH
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, which allows remote attackers to bypass intended access restrictions via an unspecified type of network traffic that had previously been denied, aka Bug ID CSCte46460
Published Jan 7, 2011
7.8
HIGHCVSS 2.0
EPSS 2.57%
Description
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, which allows remote attackers to bypass intended access restrictions via an unspecified type of network traffic that had previously been denied, aka Bug ID CSCte46460.
Affected products
No data.
AND
OR
- ≤ 8.3\(1\)
- 7.0
- 7.0\(0\)
- 7.0\(2\)
- 7.0\(4\)
- 7.0\(5\)
- 7.0\(5.2\)
- 7.0\(6.7\)
- 7.0.1
- 7.0.1.4
- 7.0.2
- 7.0.4
- 7.0.4.3
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.8
- 7.1
- 7.1\(2\)
- 7.1\(2.5\)
- 7.1\(2.27\)
- 7.1\(2.48\)
- 7.1\(2.49\)
- 7.1\(5\)
- 7.1.1
- 7.1.2
- 7.2
- 7.2\(1\)
- 7.2\(1.22\)
- 7.2\(2\)
- 7.2\(2.5\)
- 7.2\(2.7\)
- 7.2\(2.8\)
- 7.2\(2.10\)
- 7.2\(2.14\)
- 7.2\(2.15\)
- 7.2\(2.16\)
- 7.2\(2.17\)
- 7.2\(2.18\)
- 7.2\(2.19\)
- 7.2\(2.48\)
- 7.2.1
- 7.2.2
- 7.2.3
- 7.2.4
- 7.2.5
- 8.0
- 8.0.2
- 8.0.3
- 8.0.4
- 8.0.5
- 8.2\(1\)
- 8.2\(2\)
- 8.2\(3\)
- 8.2\(3.9\)
- 8.2\(4\)
- 8.2.1
- 8.2.2
- 8.2.2
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.pdf x_refsource_CONFIRM
- http://www.securityfocus.com/bid/45768 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1024963 vdb-entryx_refsource_SECTRACK
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4654 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64575 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.pdf | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/45768 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1024963 | vdb-entryx_refsource_SECTRACK | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-4654 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/64575 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2011
Updated Aug 7, 2024
Reserved Jan 7, 2011
Link CVE-2010-4689
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-4654 Assigner mitre
Published Jan 7, 2011
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-4654