This application requires Javascript for optimal performance.

Cisco.IOS.HTTP.Remote.Command.Execution

Release Date

Jan 05, 2012

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Remote Command Execution vulnerability in Cisco IOS device administration.

There exists a vulnerability in Cisco IOS devices that can be exploited by sending a carefully-constructed URL. By doing this a remote attacker can execute arbitrary commands when the HTTP server is enabled and local authorization is used.




Affected Products

Any Cisco IOS 11.3 to 12.2 (except 10.3, 11.0, 11.1, and 11.2) using local authentication databases, with the HTTP server enabled, is vulnerable to the attack.


Recommended Actions

Upgrade IOS to non-vulnerable releases.
Disable the HTTP server.
Enable TACACS+ or radius authentication.


Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2000-0984
CVE-2001-0537

Reference/s

http://www.cert.org/advisories/CA-2001-14.html
http://www.securityfocus.com/bid/2936 (BugTraq)
http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html

Reference: VID-30478