CVE-2008-4128
MEDIUM(4.3)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- CVSS 4.3 — Mittel
- EPSS 34%
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
33.7%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
4.3
Technische Schwere
SecBoard-Einordnung
CVE-2008-4128 beschreibt mehrere Cross-Site Request Forgery (CSRF)-Schwachstellen in der HTTP Administration Komponente von Cisco IOS 12.4 auf dem 871 Integrated Services Router. Diese Schwachstellen ermöglichen es entfernten Angreifern, beliebige Befehle auszuführen, indem sie spezifische 'show privilege' oder 'alias exec' Befehle über präparierte URIs senden. Die erfolgreiche Ausnutzung kann zur Ausführung von Befehlen mit erhöhten Rechten führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Referenzen
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- http://www.securityfocus.com/bid/31218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
- https://www.exploit-db.com/exploits/6476
- https://www.exploit-db.com/exploits/6477
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- http://www.securityfocus.com/bid/31218
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
- https://www.exploit-db.com/exploits/6476
- https://www.exploit-db.com/exploits/6477