CVE-2014-2138
02.04.2014, 03:58
CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | security_manager | 𝑥 ≤ 4.2 |
cisco | security_manager | 3.0.2 |
cisco | security_manager | 3.1 |
cisco | security_manager | 3.1.1 |
cisco | security_manager | 3.1.1:sp3 |
cisco | security_manager | 3.2 |
cisco | security_manager | 3.2:sp1 |
cisco | security_manager | 3.2:sp2 |
cisco | security_manager | 3.2.1 |
cisco | security_manager | 3.2.1:sp1 |
cisco | security_manager | 3.2.2 |
cisco | security_manager | 3.2.2:sp1 |
cisco | security_manager | 3.2.2:sp2 |
cisco | security_manager | 3.2.2:sp3 |
cisco | security_manager | 3.2.2:sp4 |
cisco | security_manager | 3.3 |
cisco | security_manager | 3.3:sp1 |
cisco | security_manager | 3.3:sp2 |
cisco | security_manager | 3.3.1 |
cisco | security_manager | 3.3.1:sp1 |
cisco | security_manager | 3.3.1:sp2 |
cisco | security_manager | 3.3.1:sp3 |
cisco | security_manager | 3.3.1:sp4 |
cisco | security_manager | 4.0 |
cisco | security_manager | 4.0:sp1 |
cisco | security_manager | 4.0.1 |
cisco | security_manager | 4.0.1:sp1 |
cisco | security_manager | 4.0.1:sp2 |
cisco | security_manager | 4.1 |
cisco | security_manager | 4.1:sp1 |
cisco | security_manager | 4.1:sp2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration