CVE-2009-0055

Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
ciscoironport_encryption_appliance
6.2.4
ciscoironport_encryption_appliance
6.2.4.1
ciscoironport_encryption_appliance
6.2.5
ciscoironport_encryption_appliance
6.2.6
ciscoironport_encryption_appliance
6.2.7
ciscoironport_encryption_appliance
6.2.7.1
ciscoironport_encryption_appliance
6.2.7.2
ciscoironport_encryption_appliance
6.2.7.3
ciscoironport_encryption_appliance
6.2.7.4
ciscoironport_encryption_appliance
6.2.7.5
ciscoironport_encryption_appliance
6.2.7.6
ciscoironport_encryption_appliance
6.3
ciscoironport_encryption_appliance
6.3.0.1
ciscoironport_encryption_appliance
6.3.0.2
ciscoironport_encryption_appliance
6.3.0.3
ciscoironport_encryption_appliance
6.5
ciscoironport_encryption_appliance
6.5.0.1
ciscoironport_postx
6.2.1
ciscoironport_postx
6.2.2
ciscoironport_postx
6.2.2.1
ciscoironport_postx
6.2.2.2
𝑥
= Vulnerable software versions