Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:CISCO:CATALYST-ARB-CMD

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Cisco Catalyst 3500 XL Remote Arbitrary Command

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Cisco Catalyst 3500 XL Remote Arbitrary Command


This signature detects attempts to exploit a known vulnerability against Cisco Catalyst 3500 XL. Due to insecure permissions in IOS, attackers can attempt to access a configuration file using an ordinary Web browser through a HTTP connection. Information contained in this file might lead the attackers to further compromise the device or network.

Extended Description

A vulnerability exists in the webserver configuration interface which will allow an anonymous user to execute commands. A http request which includes /exec and a known filename will reveal the contents of the particular file. In addition to disclosing the contents of files, this vulnerability could allow a user to execute arbitrary code.

Affected Products

  • Cisco Catalyst 3500 XL
  • Cisco Catalyst 3500 XL

References

  • BugTraq: 1846
  • CVE: CVE-2000-0945
  • URL: http://www.securiteam.com/exploits/5OP0L1FCAE.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out