4.3
CVSSv2

CVE-2014-2138

Published: 02/04/2014 Updated: 02/04/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and previous versions allows remote malicious users to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco security manager 3.1.1

cisco security manager 3.1

cisco security manager 3.0.2

cisco security manager 3.3.1

cisco security manager 3.3

cisco security manager 3.2.1

cisco security manager 3.2

cisco security manager 4.1

cisco security manager 4.0.1

cisco security manager 4.0

cisco security manager 3.2.2

cisco security manager

Vendor Advisories

A vulnerability in the web framework of Cisco Security Manager could allow an unauthenticated, remote attacker to inject a crafted HTTP header, which will cause a web page redirection to a possible malicious website The vulnerability is due to insufficient validation of user input before using it as an HTTP header value An attacker could exploit ...