Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-2586 | First vendor Publication | 2007-05-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2586 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:5036 | |||
Oval ID: | oval:org.mitre.oval:def:5036 | ||
Title: | Cisco IOS FTP Server Authentication Bypass Vulnerability | ||
Description: | The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259. | ||
Family: | ios | Class: | vulnerability |
Reference(s): | CVE-2007-2586 | Version: | 2 |
Platform(s): | Cisco IOS | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2008-07-29 | Cisco IOS 12.3(18) FTP Server - Remote Exploit (attached to gdb) |
OpenVAS Exploits
Date | Description |
---|---|
2008-08-22 | Name : Cisco IOS FTP Server Authentication Bypass Vulnerability File : nvt/cisco_ios_ftp_server_auth_bypass.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
35334 | Cisco IOS FTP Server User Credential Handling Remote Overflow IOS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by an unspecified condition in the FTP server which allows a remote attacker to download a copy of the startup-config file, which will disclose configuration information resulting in a loss of confidentiality. |
Snort® IPS/IDS
Date | Description |
---|---|
2018-10-17 | Multiple Products FTP MKD buffer overflow attempt RuleID : 23055-community - Revision : 10 - Type : PROTOCOL-FTP |
2014-01-10 | Multiple Products FTP MKD buffer overflow attempt RuleID : 23055 - Revision : 10 - Type : PROTOCOL-FTP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-09-01 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20070509-iosftphttp.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:24 |
|
2024-11-28 12:12:18 |
|
2023-05-09 17:27:46 |
|
2023-03-29 01:06:43 |
|
2023-03-28 12:02:16 |
|
2022-10-11 12:05:20 |
|
2022-10-11 01:02:01 |
|
2022-09-03 12:04:59 |
|
2021-10-08 12:04:13 |
|
2021-08-26 01:03:43 |
|
2021-05-04 12:05:54 |
|
2021-04-22 01:06:26 |
|
2021-04-01 01:03:15 |
|
2020-06-11 01:04:02 |
|
2020-06-10 01:02:37 |
|
2020-06-09 01:02:43 |
|
2020-05-23 02:41:12 |
|
2020-05-23 00:19:45 |
|
2017-10-11 09:23:57 |
|
2017-07-29 12:02:13 |
|
2016-06-28 16:28:14 |
|
2016-04-26 16:07:04 |
|
2014-02-17 10:40:10 |
|
2014-01-19 21:24:07 |
|
2013-05-11 10:25:25 |
|
2012-11-07 00:15:11 |
|