Vulnerability Description
The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Webns | All versions |
| Cisco | Content Services Switch 11000 | All versions |
References
- http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtmlVendor Advisory
- http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtmlVendor Advisory
FAQ
What is CVE-2002-0870?
CVE-2002-0870 is a vulnerability with a CVSS score of 7.5 (HIGH). The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileg...
How severe is CVE-2002-0870?
CVE-2002-0870 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0870?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webns, Cisco Content Services Switch 11000.