CVE-2009-2631General(aladdin / adaptive_security_appliance)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-264

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance
  • e-class_ssl_vpn
  • safenet_securewire_access_gateway
  • ssl_vpn

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
adaptive_security_appliancee-class_ssl_vpnsafenet_securewire_access_gatewayssl_vpnstonegate

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-17: 1Technical Details · 2026-02-17: 102-17
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    General

    🔍 CVE-2009-2631: Clientless SSL VPN products break... Clientless SSL VPNs fundamentally break same-origin policy by design, turning trusted domains into XSS vectors for sessi... https://zerodaysignal.com/vulnerability/CVE-2009-2631 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post highlights that clientless SSL VPNs compromise same‑origin policy, creating XSS vectors, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000060
    131 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
HWaladdinsafenet_securewire_access_gateway---
HWciscoadaptive_security_appliance---
HWsonicwalle-class_ssl_vpn---
HWsonicwallssl_vpn---
HWstonesoftstonegate---

Explore more