CVE-2009-4912

CRITICAL

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote...

Affects 1 product across 1 vendor.

BCS7.07
CVSS 2.010.0
EPSS2.5%
Percentile83th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2010. A critical vulnerability affects Cisco systems (CVE-2009-4912). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2010-GLOBAL-084312-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2009-4912?
This vulnerability was disclosed in 2010. A critical vulnerability affects Cisco systems (CVE-2009-4912). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2009-4912?
CVE-2009-4912 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.5%.
Is CVE-2009-4912 actively exploited?
No confirmed active exploitation of CVE-2009-4912 as of 2026-05-30.
How do I remediate CVE-2009-4912?
Priority: MEDIUM. Advisory: http://www.cisco.com/en/US/docs/security/asa/asa81/release/notes/asarn812.html
What systems are affected by CVE-2009-4912?
CVE-2009-4912 affects: Cisco.
Vulnerability Details
CVE IDCVE-2009-4912
BSIDBS-2010-GLOBAL-084312-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2010-06-29
Last Modified2026-04-29
ICS Relevance85%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Asa 5580
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5879 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash5b086d109c806362b5209097eb5782998e68bb144622fe37865f297f1cef3b0d91456878629beac0fac8f1a9307da8d500fc9a0daa58b4af61026c59a28a2c37
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2014-0659 10.0 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N rout... CVE-2014-0648 10.0 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 ... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →