Short Name |
HTTP:CISCO:CATALYST-ARB-CMD |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Cisco Catalyst 3500 XL Remote Arbitrary Command |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against Cisco Catalyst 3500 XL. Due to insecure permissions in IOS, attackers can attempt to access a configuration file using an ordinary Web browser through a HTTP connection. Information contained in this file might lead the attackers to further compromise the device or network.
A vulnerability exists in the webserver configuration interface which will allow an anonymous user to execute commands. A http request which includes /exec and a known filename will reveal the contents of the particular file. In addition to disclosing the contents of files, this vulnerability could allow a user to execute arbitrary code.