PoC Index

CVE-2007-2586

HIGH 9.3EPSS 14.4%

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
14.38% chance of exploitation in the next 30 days, 96th percentile
Published
2007-05-09
Updated
2024-08-07

Proof-of-concept exploits (3)

ExploitDB entries (1)

References

Related