US-CERT
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

 Other Documents
Technical Alerts

Technical Bulletins

Alerts

Security Tips

Cisco Systems, Inc. Information for VU#435052

Date Notified:2008-12-09
Date Updated:2009-03-12
Statement Date:
Status Summary:Not Vulnerable

Vendor Statement

The Cisco PSIRT has been investigating and has not found any vulnerable products. If we determine that any of our products are vulnerable, information will be available at: http://www.cisco.com/go/psirt/. Please direct any questions to psirt@cisco.com.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Access control lists can be configured to mitigate this vulnerability. The below ACLs limit access allow a proxy server to only connect make outbound connections to TCP port 80.

    access-list 111 permit tcp [ip address of proxy] any eq 80
    access-list 112 permit tcp any any gt 1023 established

    If you have feedback, comments, or additional information about this vulnerability, please send us email.
     

Produced 2009 by US-CERT, a government organization
Disclaimers and copyright information