Security Advisory

CVE-2010-1575

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-07-06 14:00:00
Last updated 2024-08-07 01:28:42
Assigner cisco
CVSS score not scored
State PUBLISHED

Description

The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted header data, as demonstrated by a ClientCert-Subject-CN header, aka Bug ID CSCsz04690.