CRLF Injection Vulnerability in Cisco Adaptive Security Appliance 5500 Series
CVE-2011-3285
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 2 May 2012
Summary
A CRLF injection vulnerability exists in the logon.html of Cisco Adaptive Security Appliances 5500 series, affecting software versions 8.0 through 8.4. This flaw allows remote attackers to inject arbitrary HTTP headers, potentially leading to HTTP response splitting attacks. Exploiting this vulnerability could mislead users and manipulate web responses, putting network security at risk. It's critical for administrators to ensure their devices are updated to mitigate potential attacks.
References
Timeline
Vulnerability published
Vulnerability Reserved