CVE-2009-4912

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
29/06/2010
Last modified:
11/04/2025

Description

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:cisco:asa_5580:*:*:*:*:*:*:*:* 8.1\(1\) (including)