{"api_version":"1","generated_at":"2026-07-23T01:32:04+00:00","cve":"CVE-2011-0348","urls":{"html":"https://cve.report/CVE-2011-0348","api":"https://cve.report/api/cve/CVE-2011-0348.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0348","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0348"},"summary":{"title":"CVE-2011-0348","description":"Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.","state":"PUBLISHED","assigner":"cisco","published_at":"2011-01-28 22:00:05","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64936","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64936","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0229","name":"http://www.vupen.com/english/advisories/2011/0229","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/70720","name":"http://osvdb.org/70720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/43052","name":"http://secunia.com/advisories/43052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Content Services Gateway Security Bypass and Denial of Service - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/46022","name":"http://www.securityfocus.com/bid/46022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Content Services Gateway Service Policy Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1024992","name":"http://securitytracker.com/id?1024992","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker: Cisco Content Services Gateway Bugs Let Users Bypass Billing Policies and Let Remote Users Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml","name":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Systems - Redirect to","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0348","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0348","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"348","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"content_services_gateway_second_generation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(11\\)md","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(15\\)md","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(22\\)md","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(22\\)mda","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(24\\)md","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(24\\)md1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.4\\(24\\)mda","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:51:07.858Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"46022","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46022"},{"name":"ADV-2011-0229","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0229"},{"name":"20110126 Cisco Content Services Gateway Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml"},{"name":"70720","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/70720"},{"name":"43052","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43052"},{"name":"1024992","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1024992"},{"name":"cisco-csg2-policy-security-bypass(64936)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64936"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-01-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"46022","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46022"},{"name":"ADV-2011-0229","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0229"},{"name":"20110126 Cisco Content Services Gateway Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml"},{"name":"70720","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/70720"},{"name":"43052","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43052"},{"name":"1024992","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1024992"},{"name":"cisco-csg2-policy-security-bypass(64936)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64936"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2011-0348","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"46022","refsource":"BID","url":"http://www.securityfocus.com/bid/46022"},{"name":"ADV-2011-0229","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0229"},{"name":"20110126 Cisco Content Services Gateway Vulnerabilities","refsource":"CISCO","url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml"},{"name":"70720","refsource":"OSVDB","url":"http://osvdb.org/70720"},{"name":"43052","refsource":"SECUNIA","url":"http://secunia.com/advisories/43052"},{"name":"1024992","refsource":"SECTRACK","url":"http://securitytracker.com/id?1024992"},{"name":"cisco-csg2-policy-security-bypass(64936)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64936"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2011-0348","datePublished":"2011-01-28T21:13:00.000Z","dateReserved":"2011-01-07T00:00:00.000Z","dateUpdated":"2024-08-06T21:51:07.858Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-01-28 22:00:05","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(11\\)md:*:*:*:*:*:*:*","matchCriteriaId":"92AD4889-F6B6-4497-A589-8632A1850965"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(15\\)md:*:*:*:*:*:*:*","matchCriteriaId":"DE0233F4-AA5D-47C3-934A-4BA793DD4A2E"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(22\\)md:*:*:*:*:*:*:*","matchCriteriaId":"498A43E2-5A03-46C9-B60D-8E7CE79F1705"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(22\\)mda:*:*:*:*:*:*:*","matchCriteriaId":"6EB30791-A691-42DD-8714-B173242EDBBF"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(24\\)md:*:*:*:*:*:*:*","matchCriteriaId":"539454C8-EA90-4146-9429-72465CF555FE"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(24\\)md1:*:*:*:*:*:*:*","matchCriteriaId":"4E44F5F4-D7FE-4B9C-BA65-2365EF7A8092"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:12.4\\(24\\)mda:*:*:*:*:*:*:*","matchCriteriaId":"D0F2A946-AD8A-4644-8630-5951B66E4B34"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:content_services_gateway_second_generation:*:*:*:*:*:*:*:*","matchCriteriaId":"A7759766-DE4B-42DE-BFB9-0EA6E08C89F6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"348","Ordinal":"1","Title":"CVE-2011-0348","CVE":"CVE-2011-0348","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"348","Ordinal":"1","NoteData":"Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.","Type":"Description","Title":"CVE-2011-0348"},{"CveYear":"2011","CveId":"348","Ordinal":"2","NoteData":"2011-01-28","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"348","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}