PT-2000-1857 · Cisco · Catalyst 3500 Xl

Published

2000-12-19

·

Updated

2017-10-10

·

CVE-2000-0945

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Catalyst 3500 XL switches (affected versions not specified)
Description The issue concerns the web configuration interface of the Catalyst 3500 XL switches, which allows remote attackers to execute arbitrary commands without authentication when the enable password is not set. This can be achieved by accessing a URL containing the /exec/ directory.
Recommendations For Catalyst 3500 XL switches, set an enable password to prevent unauthorized access and execution of arbitrary commands.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0945

Affected Products

Catalyst 3500 Xl