CVE-2010-4680
Last modified
CVE-2010-4680 is a vulnerability of currently unknown severity. The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended access restrictions via CIFS requests, aka Bug ID CSCsz80777.. EPSS estimates a 2.80% chance of exploitation in the next 30 days.
Description
The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS shares even when CIFS file browsing has been disabled, which allows remote authenticated users to bypass intended access restrictions via CIFS requests, aka Bug ID CSCsz80777.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance Software | <= 8.2\(2\) |
| Cisco | Adaptive Security Appliance Software | 7.0 |
| Cisco | Adaptive Security Appliance Software | 7.0\(0\) |
| Cisco | Adaptive Security Appliance Software | 7.0\(2\) |
| Cisco | Adaptive Security Appliance Software | 7.0\(4\) |
| Cisco | Adaptive Security Appliance Software | 7.0\(5\) |
| Cisco | Adaptive Security Appliance Software | 7.0\(5.2\) |
| Cisco | Adaptive Security Appliance Software | 7.0\(6.7\) |
| Cisco | Adaptive Security Appliance Software | 7.0.1 |
| Cisco | Adaptive Security Appliance Software | 7.0.1.4 |
| Cisco | Adaptive Security Appliance Software | 7.0.2 |
| Cisco | Adaptive Security Appliance Software | 7.0.4 |
| Cisco | Adaptive Security Appliance Software | 7.0.4.3 |
| Cisco | Adaptive Security Appliance Software | 7.0.5 |
| Cisco | Adaptive Security Appliance Software | 7.0.6 |
| Cisco | Adaptive Security Appliance Software | 7.0.7 |
| Cisco | Adaptive Security Appliance Software | 7.0.8 |
| Cisco | Adaptive Security Appliance Software | 7.1 |
| Cisco | Adaptive Security Appliance Software | 7.1\(2\) |
| Cisco | Adaptive Security Appliance Software | 7.1\(2.5\) |
| Cisco | Adaptive Security Appliance Software | 7.1\(2.27\) |
| Cisco | Adaptive Security Appliance Software | 7.1\(2.48\) |
| Cisco | Adaptive Security Appliance Software | 7.1\(2.49\) |
| Cisco | Adaptive Security Appliance Software | 7.1\(5\) |
| Cisco | Adaptive Security Appliance Software | 7.1.1 |
| Cisco | Adaptive Security Appliance Software | 7.1.2 |
| Cisco | Adaptive Security Appliance Software | 7.2 |
| Cisco | Adaptive Security Appliance Software | 7.2\(1\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(1.22\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.5\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.7\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.8\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.10\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.14\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.15\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.16\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.17\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.18\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.19\) |
| Cisco | Adaptive Security Appliance Software | 7.2\(2.48\) |
| Cisco | Adaptive Security Appliance Software | 7.2.1 |
| Cisco | Adaptive Security Appliance Software | 7.2.2 |
| Cisco | Adaptive Security Appliance Software | 7.2.3 |
| Cisco | Adaptive Security Appliance Software | 7.2.4 |
| Cisco | Adaptive Security Appliance Software | 7.2.5 |
| Cisco | Adaptive Security Appliance Software | 8.0 |
| Cisco | Adaptive Security Appliance Software | 8.0.2 |
| Cisco | Adaptive Security Appliance Software | 8.0.3 |
| Cisco | Adaptive Security Appliance Software | 8.0.4 |
Showing 50 of 56 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4680?
How severe is CVE-2010-4680?
How do I fix CVE-2010-4680?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4674Unspecified vulnerability on Cisco Adaptive Security Applian…
- CVE-2010-4675Cisco Adaptive Security Appliances (ASA) 5500 series devices…
- CVE-2010-4676Unspecified vulnerability on Cisco Adaptive Security Applian…
- CVE-2010-4677emWEB on Cisco Adaptive Security Appliances (ASA) 5500 serie…
- CVE-2010-4678Cisco Adaptive Security Appliances (ASA) 5500 series devices…
- CVE-2010-4679Cisco Adaptive Security Appliances (ASA) 5500 series devices…
- CVE-2010-4681Unspecified vulnerability on Cisco Adaptive Security Applian…
- CVE-2010-4682Memory leak on Cisco Adaptive Security Appliances (ASA) 5500…
- CVE-2010-4683Memory leak in Cisco IOS before 15.0(1)XA5 might allow remot…
- CVE-2010-4684Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is …
- CVE-2010-4685Cisco IOS before 15.0(1)XA1 does not clear the public key ca…
- CVE-2010-4686CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 doe…
Are you affected by CVE-2010-4680?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
