PT-2000-1857 · Cisco · Catalyst 3500 Xl
Published
2000-12-19
·
Updated
2017-10-10
·
CVE-2000-0945
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Catalyst 3500 XL switches (affected versions not specified)
Description
The issue concerns the web configuration interface of the Catalyst 3500 XL switches, which allows remote attackers to execute arbitrary commands without authentication when the enable password is not set. This can be achieved by accessing a URL containing the /exec/ directory.
Recommendations
For Catalyst 3500 XL switches, set an enable password to prevent unauthorized access and execution of arbitrary commands.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Catalyst 3500 Xl