← Back

CVE-2011-3285

nvd nist
Published: May 2, 2012Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCth63101.

Affected (33)

2 products
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 8.0.2
Version 8.0.3
Version 8.0.4
Version 8.0.5
Version 8.0
Version 8.0(2)
Version 8.0(3)
Version 8.0(4)
Version 8.0(5)
Version 8.1
Version 8.2.1
Version 8.2.2
Version 8.2.2 interim
Version 8.2.3
Version 8.2(1)
Version 8.2(2)
Version 8.2(3.9)
Version 8.2(3)
Version 8.2(4.1)
Version 8.2(4.4)
Version 8.2(4)
Version 8.2(5)
Version 8.3.1
Version 8.3.1 interim
Version 8.3.2
Version 8.3(1)
Version 8.3(2)
Version 8.4
Version 8.4(1.11)
Version 8.4(1)
Version 8.4(2.11)
Version 8.4(2)
All versions

Timeline

No history available yet.