CVE-2010-2822 describes an unspecified vulnerability in the RTSP inspection feature of Cisco Application Control Engine (ACE) Modules and ACE 4710 appliances. This flaw allows remote attackers to trigger a denial of service, specifically a device reload, by sending specially crafted RTSP packets over TCP. The vulnerability affects Cisco ACE Modules running software prior to A2(3.2) and ACE 4710 appliances with software before A3(2.6). With a CVSS score of 7.8, this vulnerability is considered high severity. It has a network attack vector and low attack complexity, requiring no authentication. The primary impact is a complete loss of availability due to the device reloading. There is no evidence of active exploitation, and no public exploit code is available for this CVE, including in Metasploit or ExploitDB. Community discussion and media coverage are minimal, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:ace_4710:*:*:*:*:*:*:*:* | ||
a1\(2.0\)CPE matchmatch criteria | cpe:2.3:h:cisco:ace_4710:a1\(2.0\):*:*:*:*:*:*:* | ||
a1\(8.0\)CPE matchmatch criteria | cpe:2.3:h:cisco:ace_4710:a1\(8.0\):*:*:*:*:*:*:* | ||
a3\(2.0\)CPE matchmatch criteria | cpe:2.3:h:cisco:ace_4710:a3\(2.0\):*:*:*:*:*:*:* | ||
a3\(2.5\)CPE matchmatch criteria | cpe:2.3:h:cisco:ace_4710:a3\(2.5\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.