CRLF Injection Vulnerability in Cisco Adaptive Security Appliance 5500 Series
CVE-2011-3285

Currently unrated

Key Information:

Summary

A CRLF injection vulnerability exists in the logon.html of Cisco Adaptive Security Appliances 5500 series, affecting software versions 8.0 through 8.4. This flaw allows remote attackers to inject arbitrary HTTP headers, potentially leading to HTTP response splitting attacks. Exploiting this vulnerability could mislead users and manipulate web responses, putting network security at risk. It's critical for administrators to ensure their devices are updated to mitigate potential attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.