SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3457

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request,…

MEDIUM 5.0EPSS 4.19%

Does this matter?

Lower severity and a low EPSS score (4.19%). Track it; it rarely justifies an emergency change on its own.

Description

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
4.19% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
cisco/ace web application firewall · cisco/ace xml gateway
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.