CVE-2011-0348
Summary
| CVE | CVE-2011-0348 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-28 22:00:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Content Services Gateway Second Generation | All | All | All | All |
| Operating System | Cisco | Ios | 12.4\(11\)md | All | All | All |
| Operating System | Cisco | Ios | 12.4\(15\)md | All | All | All |
| Operating System | Cisco | Ios | 12.4\(22\)md | All | All | All |
| Operating System | Cisco | Ios | 12.4\(22\)mda | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md1 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/70720 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cisco Content Services Gateway Security Bypass and Denial of Service - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Cisco Content Services Gateway Service Policy Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker: Cisco Content Services Gateway Bugs Let Users Bypass Billing Policies and Let Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Cisco Systems - Redirect to | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.