6.4
CVSSv2

CVE-2011-0348

Published: 28/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD prior to 12.4(24)MD3, 12.4(22)MDA prior to 12.4(22)MDA5, and 12.4(24)MDA prior to 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote malicious users to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.4\\(24\\)md

cisco ios 12.4\\(24\\)md1

cisco ios 12.4\\(24\\)mda

cisco ios 12.4\\(22\\)mda

cisco ios 12.4\\(15\\)md

cisco ios 12.4\\(22\\)md

cisco ios 12.4\\(11\\)md

Vendor Advisories

A service policy bypass vulnerability exists in the Cisco Content Services Gateway - Second Generation (CSG2), which runs on the Cisco Service and Application Module for IP (SAMI) Under certain configurations this vulnerability could allow: Customers to access sites that would normally match a billing policy to be accessed without ...