MEDIUM · 5.0

CVE-2010-4690

The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appl...

Vulnerability Description

The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appliance (WSA), which might allow remote attackers to obtain sensitive information via a HEAD request, aka Bug ID CSCte53635.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoAdaptive Security Appliance Software<= 8.3\(1\)
Cisco5500 Series Adaptive Security ApplianceAll versions
CiscoAsa 5500All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4690?

CVE-2010-4690 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly authenticate HTTP requests from a Web Security appl...

How severe is CVE-2010-4690?

CVE-2010-4690 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4690?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Adaptive Security Appliance Software, Cisco 5500 Series Adaptive Security Appliance, Cisco Asa 5500.