Vulnerabilities > Cisco > ACE 4710

DATE CVE VULNERABILITY TITLE RISK
2010-08-17 CVE-2010-2825 Unspecified vulnerability in Cisco ACE 4710 and ACE Module
Unspecified vulnerability in the SIP inspection feature on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2(2.x) before A2(2.3), and A2(3.x) before A2(3.1) for Catalyst 6500 series switches and 7600 series routers, and the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(2.4), allows remote attackers to cause a denial of service (device reload) via crafted SIP packets over (1) TCP or (2) UDP, aka Bug IDs CSCta65603 and CSCta71569.
network
low complexity
cisco
7.8
2010-08-17 CVE-2010-2823 Unspecified vulnerability in Cisco ACE 4710
Unspecified vulnerability in the deep packet inspection feature on the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(2.6) allows remote attackers to cause a denial of service (device reload) via crafted HTTP packets, related to HTTP, RTSP, and SIP inspection, aka Bug ID CSCtb54493.
network
low complexity
cisco
7.8
2010-08-17 CVE-2010-2822 Unspecified vulnerability in Cisco ACE 4710 and ACE Module
Unspecified vulnerability in the RTSP inspection feature on the Cisco Application Control Engine (ACE) Module with software before A2(3.2) for Catalyst 6500 series switches and 7600 series routers, and the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(2.6), allows remote attackers to cause a denial of service (device reload) via crafted RTSP packets over TCP, aka Bug IDs CSCta85227 and CSCtg14858.
network
low complexity
cisco
7.8
2010-07-06 CVE-2010-2629 Improper Input Validation vulnerability in Cisco ACE 4710 and Content Services Switch 11500
The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers.
network
low complexity
cisco CWE-20
7.5
2010-07-06 CVE-2010-1576 Improper Input Validation vulnerability in Cisco ACE 4710 and Content Services Switch 11500
The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.
network
low complexity
cisco CWE-20
7.5
2009-02-26 CVE-2009-0742 Cryptographic Issues vulnerability in Cisco ACE 4710 and Application Control Engine Module
The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.
network
low complexity
cisco CWE-310
7.8
2009-02-26 CVE-2009-0625 Code Injection vulnerability in Cisco ACE 4710 and Application Control Engine Module
Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8.0) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv3 packet.
network
low complexity
cisco CWE-94
7.8
2009-02-26 CVE-2009-0624 Remote vulnerability in Multiple Cisco ACE Products
Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv1 packet.
network
low complexity
cisco
6.8
2009-02-26 CVE-2009-0623 Remote vulnerability in Multiple Cisco ACE Products
Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SSH packet.
network
low complexity
cisco
7.8
2009-02-26 CVE-2009-0622 Remote vulnerability in Multiple Cisco ACE Products
Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8a) allows remote authenticated users to execute arbitrary operating-system commands through a command line interface (CLI).
network
low complexity
cisco
critical
9.0