Search:     Advanced search
server monitoring

Cisco IOS HTTP Configuration Unauthorized Administrative Access

Article ID: 10700
Last updated: 27 Jan, 2009
Views: 459
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Cisco IOS HTTP Configuration Unauthorized Administrative Access

This script is Copyright (C) 2001-2008 Tenable Network Security, Inc.

FamilyCISCO
Plugin ID10700
Bugtraq ID2936
CVE IDCVE-2001-0537

Description:
Synopsis :

The remote router allows authentication to be bypassed and arbitrary
commands to be executed.

Description :

It is possible to execute arbitrary commands on the remote Cisco
router. An attacker may leverage this issue to disable network access
via this device or lock legitimate users out of the router.

See also :

http://www.cisco.com/warp/public/707/cisco-sa-20010627-ios-http-level.shtml

Solution :

Disable the web configuration interface completely.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Cisco Multiple Devices Crafted IP Option Multiple Remote Code...     Cisco Gigabit Switch Routers (GSR) Line Card Failure ACL Bypas...