CVE-2009-0056

Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.4:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.4.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.5:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.6:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.3:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.5:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.2.7.6:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.3:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.3.0.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.3.0.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.3.0.3:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.5:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_encryption_appliance:6.5.0.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_postx:6.2.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_postx:6.2.2:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_postx:6.2.2.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ironport_postx:6.2.2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:58

Type Values Removed Values Added
References () http://osvdb.org/51398 - () http://osvdb.org/51398 -
References () http://secunia.com/advisories/33479 - () http://secunia.com/advisories/33479 -
References () http://securitytracker.com/id?1021594 - () http://securitytracker.com/id?1021594 -
References () http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml - Vendor Advisory () http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml - Vendor Advisory
References () http://www.securityfocus.com/bid/33268 - () http://www.securityfocus.com/bid/33268 -
References () http://www.vupen.com/english/advisories/2009/0140 - () http://www.vupen.com/english/advisories/2009/0140 -

Information

Published : 2009-01-16 21:30

Updated : 2024-11-21 00:58


NVD link : CVE-2009-0056

Mitre link : CVE-2009-0056

CVE.ORG link : CVE-2009-0056


JSON object : View

Products Affected

cisco

  • ironport_encryption_appliance
  • ironport_postx
CWE
CWE-352

Cross-Site Request Forgery (CSRF)