Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-0348


Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.


Published

2011-01-28T22:00:05.787

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.4\(11\)md Yes
Operating System cisco ios 12.4\(15\)md Yes
Operating System cisco ios 12.4\(22\)md Yes
Operating System cisco ios 12.4\(22\)mda Yes
Operating System cisco ios 12.4\(24\)md Yes
Operating System cisco ios 12.4\(24\)md1 Yes
Operating System cisco ios 12.4\(24\)mda Yes
Hardware cisco content_services_gateway_second_generation * No

References