← Vulnerability feed

Vulnerability record · CVE-2010-1576 · published 6 July 2010

CVE-2010-1576: Cisco content services switch 11500 improper input validation vulnerability

Cisco · Content Services Switch 11500

The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.

7.5 CVSS 2.0 High EPSS 1.8% · top 21.8% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-1576 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0621Cisco ace 4710 vulnerabilityCisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web man…EPSS 1.8%9.0CVE-2009-0622Cisco application control engine module vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.5%7.8CVE-2010-2823Cisco ace 4710 vulnerabilityUnspecified vulnerability in the deep packet inspection feature on the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(…EPSS 1.8%7.8CVE-2010-2825Cisco ace module vulnerabilityUnspecified vulnerability in the SIP inspection feature on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2…EPSS 1.2%7.8CVE-2010-2822Cisco ace 4710 vulnerabilityUnspecified vulnerability in the RTSP inspection feature on the Cisco Application Control Engine (ACE) Module with software before A2(3.2) for Cataly…EPSS 1.8%7.8CVE-2009-0625Cisco ace 4710 code injection vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.7%7.8CVE-2009-0623Cisco ace 4710 vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 471…EPSS 1.3%7.8CVE-2009-0742Cisco application control engine module vulnerabilityThe username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2010-1576), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.