Skip to content

CVE-2014-2137

CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0021 (0.2%)
Percentil: 43.4%
EPSS: 2026-05-06

Afecta

cisco:web_security_virtual_appliancecisco:web_security_appliance

Descripción técnica

CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.

Publicada: 2/4/2014, 3:58:17
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo