This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:CISCO:IOS-ADMIN-ACCESS
|
Severity |
Major
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Cisco IOS HTTP Configuration Administrative Access
|
Release Date |
2003/04/22
|
Update Number |
1213
|
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Cisco IOS HTTP Configuration Administrative Access
This signature detects connection requests to the Cisco IOS management interface through HTTP. Numerous vulnerabilities in the HTTP interface allow remote attackers, if successful, to gain complete control of the router.
Extended Description
IOS is router firmware developed and distributed by Cisco Systems. IOS functions on numerous Cisco devices, including routers and switches.
It is possible to gain full remote administrative access on devices using affected releases of IOS. By using a URL of http://router.address/level/$NUMBER/exec/.... where $NUMBER is an integer between 16 and 99, it is possible for a remote user to gain full administrative access.
This problem makes it possible for a remote user to gain full administrative privileges, which may lead to further compromise of the network or result in a denial of service.
Affected Products
- Cisco ios 11.3
- Cisco ios 11.3AA
- Cisco ios 11.3DA
- Cisco ios 11.3DB
- Cisco ios 11.3HA
- Cisco ios 11.3MA
- Cisco ios 11.3NA
- Cisco ios 11.3T
- Cisco ios 11.3XA
- Cisco ios 12.0
- Cisco ios 12.0(10)W5(18G)
- Cisco ios 12.0(14)W5(20)
- Cisco ios 12.0(5)XK
- Cisco ios 12.0(7)XK
- Cisco ios 12.0DA
- Cisco ios 12.0DB
- Cisco ios 12.0DC
- Cisco ios 12.0S
- Cisco ios 12.0SC
- Cisco ios 12.0SL
- Cisco ios 12.0ST
- Cisco ios 12.0T
- Cisco ios 12.0WC
- Cisco ios 12.0WT
- Cisco ios 12.0XA
- Cisco ios 12.0XB
- Cisco ios 12.0XC
- Cisco ios 12.0XD
- Cisco ios 12.0XE
- Cisco ios 12.0XF
- Cisco ios 12.0XG
- Cisco ios 12.0XH
- Cisco ios 12.0XI
- Cisco ios 12.0XJ
- Cisco ios 12.0XL
- Cisco ios 12.0XM
- Cisco ios 12.0XN
- Cisco ios 12.0XP
- Cisco ios 12.0XQ
- Cisco ios 12.0XR
- Cisco ios 12.0XS
- Cisco ios 12.0XU
- Cisco ios 12.0XV
- Cisco ios 12.1
- Cisco ios 12.1AA
- Cisco ios 12.1CX
- Cisco ios 12.1DA
- Cisco ios 12.1DB
- Cisco ios 12.1DC
- Cisco ios 12.1E
- Cisco ios 12.1EC
- Cisco ios 12.1EX
- Cisco ios 12.1EY
- Cisco ios 12.1EZ
- Cisco ios 12.1T
- Cisco ios 12.1XA
- Cisco ios 12.1XB
- Cisco ios 12.1XC
- Cisco ios 12.1XD
- Cisco ios 12.1XE
- Cisco ios 12.1XF
- Cisco ios 12.1XG
- Cisco ios 12.1XH
- Cisco ios 12.1XI
- Cisco ios 12.1XJ
- Cisco ios 12.1XK
- Cisco ios 12.1XL
- Cisco ios 12.1XM
- Cisco ios 12.1XP
- Cisco ios 12.1XQ
- Cisco ios 12.1XR
- Cisco ios 12.1XS
- Cisco ios 12.1XT
- Cisco ios 12.1XU
- Cisco ios 12.1XV
- Cisco ios 12.1XW
- Cisco ios 12.1XX
- Cisco ios 12.1XY
- Cisco ios 12.1XZ
- Cisco ios 12.1YA
- Cisco ios 12.1YB
- Cisco ios 12.1YC
- Cisco ios 12.1YD
- Cisco ios 12.1YF
- Cisco ios 12.2
- Cisco ios 12.2T
- Cisco ios 12.2XA
- Cisco ios 12.2XD
- Cisco ios 12.2XE
- Cisco ios 12.2XH
- Cisco ios 12.2XQ
References