peter bassill · operator
$ cve CVE-2009-1203 JSON

CVE-2009-1203 EXPLOIT

6.0
MEDIUM · CVSS 2.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.

Scoring

CVSS6.0 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS3.78% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2009-06-25
Last modified2026-06-16

Affected (1)

VendorProduct
ciscoadaptive security appliance

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD