← Vulnerability feed

Vulnerability record · CVE-2010-2629 · published 6 July 2010

CVE-2010-2629: Cisco content services switch 11500 improper input validation vulnerability

Cisco · Content Services Switch 11500

The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1576.

7.5 CVSS 2.0 High EPSS 1.5% · top 27.0% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1576.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2629 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0621Cisco ace 4710 vulnerabilityCisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web man…EPSS 1.8%9.0CVE-2009-0622Cisco application control engine module vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.5%7.8CVE-2010-2823Cisco ace 4710 vulnerabilityUnspecified vulnerability in the deep packet inspection feature on the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(…EPSS 1.8%7.8CVE-2010-2825Cisco ace module vulnerabilityUnspecified vulnerability in the SIP inspection feature on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2…EPSS 1.2%7.8CVE-2010-2822Cisco ace 4710 vulnerabilityUnspecified vulnerability in the RTSP inspection feature on the Cisco Application Control Engine (ACE) Module with software before A2(3.2) for Cataly…EPSS 1.8%7.8CVE-2009-0625Cisco ace 4710 code injection vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…EPSS 1.7%7.8CVE-2009-0623Cisco ace 4710 vulnerabilityUnspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 471…EPSS 1.3%7.8CVE-2009-0742Cisco application control engine module vulnerabilityThe username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2010-2629), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.