CVE Vulnerabilities

CVE-2009-2863

Improper Authentication

Published: Sep 28, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
IosCisco12.0xk (including)12.0xk (including)
IosCisco12.0xr (including)12.0xr (including)
IosCisco12.1 (including)12.1 (including)
IosCisco12.1e (including)12.1e (including)
IosCisco12.1ex (including)12.1ex (including)
IosCisco12.1t (including)12.1t (including)
IosCisco12.1xc (including)12.1xc (including)
IosCisco12.1xh (including)12.1xh (including)
IosCisco12.1xi (including)12.1xi (including)
IosCisco12.1xj (including)12.1xj (including)
IosCisco12.1xm (including)12.1xm (including)
IosCisco12.1xp (including)12.1xp (including)
IosCisco12.1xr (including)12.1xr (including)
IosCisco12.1yb (including)12.1yb (including)
IosCisco12.1yd (including)12.1yd (including)
IosCisco12.1yf (including)12.1yf (including)
IosCisco12.1yi (including)12.1yi (including)
IosCisco12.2 (including)12.2 (including)
IosCisco12.2b (including)12.2b (including)
IosCisco12.2bw (including)12.2bw (including)
IosCisco12.2cz (including)12.2cz (including)
IosCisco12.2dd (including)12.2dd (including)
IosCisco12.2ex (including)12.2ex (including)
IosCisco12.2ey (including)12.2ey (including)
IosCisco12.2fz (including)12.2fz (including)
IosCisco12.2ira (including)12.2ira (including)
IosCisco12.2irb (including)12.2irb (including)
IosCisco12.2irc (including)12.2irc (including)
IosCisco12.2ixa (including)12.2ixa (including)
IosCisco12.2ixb (including)12.2ixb (including)
IosCisco12.2ixc (including)12.2ixc (including)
IosCisco12.2ixd (including)12.2ixd (including)
IosCisco12.2ixe (including)12.2ixe (including)
IosCisco12.2ixf (including)12.2ixf (including)
IosCisco12.2ixg (including)12.2ixg (including)
IosCisco12.2s (including)12.2s (including)
IosCisco12.2sbc (including)12.2sbc (including)
IosCisco12.2se (including)12.2se (including)
IosCisco12.2sec (including)12.2sec (including)
IosCisco12.2sed (including)12.2sed (including)
IosCisco12.2see (including)12.2see (including)
IosCisco12.2sef (including)12.2sef (including)
IosCisco12.2seg (including)12.2seg (including)
IosCisco12.2sg (including)12.2sg (including)
IosCisco12.2sga (including)12.2sga (including)
IosCisco12.2sq (including)12.2sq (including)
IosCisco12.2sra (including)12.2sra (including)
IosCisco12.2srb (including)12.2srb (including)
IosCisco12.2src (including)12.2src (including)
IosCisco12.2su (including)12.2su (including)
IosCisco12.2sx (including)12.2sx (including)
IosCisco12.2sxa (including)12.2sxa (including)
IosCisco12.2sxb (including)12.2sxb (including)
IosCisco12.2sxd (including)12.2sxd (including)
IosCisco12.2sxe (including)12.2sxe (including)
IosCisco12.2sxf (including)12.2sxf (including)
IosCisco12.2sxh (including)12.2sxh (including)
IosCisco12.2sxi (including)12.2sxi (including)
IosCisco12.2t (including)12.2t (including)
IosCisco12.2tpc (including)12.2tpc (including)
IosCisco12.2xa (including)12.2xa (including)
IosCisco12.2xb (including)12.2xb (including)
IosCisco12.2xd (including)12.2xd (including)
IosCisco12.2xe (including)12.2xe (including)
IosCisco12.2xg (including)12.2xg (including)
IosCisco12.2xj (including)12.2xj (including)
IosCisco12.2xk (including)12.2xk (including)
IosCisco12.2xl (including)12.2xl (including)
IosCisco12.2xm (including)12.2xm (including)
IosCisco12.2xo (including)12.2xo (including)
IosCisco12.2xq (including)12.2xq (including)
IosCisco12.2xt (including)12.2xt (including)
IosCisco12.2xv (including)12.2xv (including)
IosCisco12.2xw (including)12.2xw (including)
IosCisco12.2ya (including)12.2ya (including)
IosCisco12.2yb (including)12.2yb (including)
IosCisco12.2yc (including)12.2yc (including)
IosCisco12.2ye (including)12.2ye (including)
IosCisco12.2yf (including)12.2yf (including)
IosCisco12.2yh (including)12.2yh (including)
IosCisco12.2yl (including)12.2yl (including)
IosCisco12.2ym (including)12.2ym (including)
IosCisco12.2yn (including)12.2yn (including)
IosCisco12.2yq (including)12.2yq (including)
IosCisco12.2yu (including)12.2yu (including)
IosCisco12.2yv (including)12.2yv (including)
IosCisco12.2yx (including)12.2yx (including)
IosCisco12.2yz (including)12.2yz (including)
IosCisco12.2zd (including)12.2zd (including)
IosCisco12.2zh (including)12.2zh (including)
IosCisco12.2zj (including)12.2zj (including)
IosCisco12.2zl (including)12.2zl (including)
IosCisco12.2zy (including)12.2zy (including)
IosCisco12.2zya (including)12.2zya (including)
IosCisco12.3 (including)12.3 (including)
IosCisco12.3b (including)12.3b (including)
IosCisco12.3jk (including)12.3jk (including)
IosCisco12.3t (including)12.3t (including)
IosCisco12.3tpc (including)12.3tpc (including)
IosCisco12.3va (including)12.3va (including)
IosCisco12.3xa (including)12.3xa (including)
IosCisco12.3xc (including)12.3xc (including)
IosCisco12.3xd (including)12.3xd (including)
IosCisco12.3xe (including)12.3xe (including)
IosCisco12.3xf (including)12.3xf (including)
IosCisco12.3xg (including)12.3xg (including)
IosCisco12.3xk (including)12.3xk (including)
IosCisco12.3xl (including)12.3xl (including)
IosCisco12.3xq (including)12.3xq (including)
IosCisco12.3xr (including)12.3xr (including)
IosCisco12.3xx (including)12.3xx (including)
IosCisco12.3ya (including)12.3ya (including)
IosCisco12.3yd (including)12.3yd (including)
IosCisco12.3yg (including)12.3yg (including)
IosCisco12.3yh (including)12.3yh (including)
IosCisco12.3yi (including)12.3yi (including)
IosCisco12.3yk (including)12.3yk (including)
IosCisco12.3ym (including)12.3ym (including)
IosCisco12.3yt (including)12.3yt (including)
IosCisco12.3yz (including)12.3yz (including)
IosCisco12.4 (including)12.4 (including)
IosCisco12.4mr (including)12.4mr (including)
IosCisco12.4t (including)12.4t (including)
IosCisco12.4xa (including)12.4xa (including)
IosCisco12.4xd (including)12.4xd (including)
IosCisco12.4xe (including)12.4xe (including)
IosCisco12.4xf (including)12.4xf (including)
IosCisco12.4xj (including)12.4xj (including)
IosCisco12.4xk (including)12.4xk (including)
IosCisco12.4xt (including)12.4xt (including)
IosCisco12.4xv (including)12.4xv (including)
IosCisco12.4xw (including)12.4xw (including)
IosCisco12.4xy (including)12.4xy (including)
IosCisco12.4xz (including)12.4xz (including)
IosCisco12.4ya (including)12.4ya (including)
IosCisco12.4yb (including)12.4yb (including)

Potential Mitigations

References