4.3
CVSSv2

CVE-2014-2137

Published: 02/04/2014 Updated: 02/04/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and previous versions allows remote malicious users to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco web security virtual appliance 7.1.0

cisco web security virtual appliance 7.1.2

cisco web security virtual appliance 7.1.4

cisco web security virtual appliance 7.5.0

cisco web security virtual appliance 7.1.1

cisco web security virtual appliance

cisco web security appliance -

cisco web security virtual appliance 7.5.1

cisco web security virtual appliance 7.1.3

Vendor Advisories

A vulnerability in the web framework of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to inject a crafted HTTP header that could cause a web page redirection to a possible malicious website The vulnerability is due to insufficient validation of user input before it is used as an HTTP header value An attacker ...