The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended access restrictions via CIFS requests, aka Bug ID CSCsz80777.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2011-01-07 04:00
Updated : 2017-08-16 18:33
NVD link : CVE-2010-4680
Mitre link : CVE-2010-4680
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- asa_5500
- adaptive_security_appliance_software
- 5500_series_adaptive_security_appliance