6.4
CVSSv2

CVE-2006-2322

Published: 12/05/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and previous versions, and 3120 5.0.0 and previous versions, has a default configuration that allows remote malicious users to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco application velocity system 3110 4.0

cisco application velocity system 3110 5.0

cisco application velocity system 3120 5.0

Vendor Advisories

Cisco Application Velocity System's (AVS) default configuration allows transparent relay of TCP connections to any reachable destination TCP port if the receiving TCP service can process requests embedded in a HTTP POST method message This issue does not require a software upgrade and can be mitigated by a configuration command for all aff ...