|
Cisco Application Velocity System Open Relay Security Issue
|
|
Secunia Advisory:
|
SA20079
|
|
|
Release Date:
|
2006-05-11
|
|
Last Update:
|
2006-05-15
|
|
Popularity:
|
5,864 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Security Bypass Spoofing
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Cisco AVS 3110 Application Velocity System Cisco AVS 3120 Application Velocity System
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: A security issue has been reported in Cisco Application Velocity System (AVS), which can be exploited by malicious people to use the device as an open relay.
The problem is caused due to insecure default settings allowing anyone to use the device as an open relay to any TCP service able to process data embedded in HTTP POST requests.
The security issue affects the following products:
* AVS 3110 versions 4.0 and 5.0 (and prior)
* AVS 3120 version 5.0.0 (and prior)
NOTE: According to Cisco PSIRT, the security issue is actively exploited to send unsolicited commercial e-mails and obscure the true originator.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|