peter bassill · operator
$ cve CVE-2006-0515 JSON

CVE-2006-0515 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the request from being sent to Websense for inspection, aka bugs CSCsc67612, CSCsc68472, and CSCsd81734.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.79% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-09
Last modified2026-06-16

Affected (4)

VendorProduct
ciscoadaptive security appliance software
ciscofirewall services module
ciscopix firewall
ciscopix firewall software

Public exploits

SourceTitleDate
exploit-dbCisco - WebSense Content Filtering Bypass2006-05-08

References

→ the Explorer  ·  watch your stack  ·  NVD