CVE-2010-1576 describes a vulnerability in Cisco Content Services Switch (CSS) 11500 and Application Control Engine (ACE) 4710 that allows remote attackers to bypass header insertions or conduct HTTP request smuggling. This is due to improper handling of line feed (LF) and carriage return (CR) characters as alternatives to the standard CRLF sequence in HTTP headers. With a CVSS score of 7.5, this vulnerability is considered high severity, enabling potential information disclosure, integrity compromise, and denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.20.3.03CPE matchmatch criteria | cpe:2.3:h:cisco:content_services_switch_11500:*:*:*:*:*:*:*:* | ||
8.20.0.01CPE matchmatch criteria | cpe:2.3:h:cisco:content_services_switch_11500:8.20.0.01:*:*:*:*:*:*:* | ||
08.20.1.01CPE matchmatch criteria | cpe:2.3:h:cisco:content_services_switch_11500:08.20.1.01:*:*:*:*:*:*:* | ||
8.20.1.01CPE matchmatch criteria | cpe:2.3:h:cisco:content_services_switch_11500:8.20.1.01:*:*:*:*:*:*:* | ||
8.20.2.01CPE matchmatch criteria | cpe:2.3:h:cisco:content_services_switch_11500:8.20.2.01:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.