Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8p3v-g4jm-c2m8

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

EPSS

Процентиль: 66%
0.00527
Низкий

Связанные уязвимости

nvd
больше 23 лет назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

EPSS

Процентиль: 66%
0.00527
Низкий