CVE-2008-4128
בינונית 4.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco IOS Cross-Site Request Forgery Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
תיאור (מקור, אנגלית)
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 33% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-352
מוצרים מושפעים
cisco: ios; cisco: 871 integrated services router
קישורים
- http://www.securityfocus.com/bid/31218 Broken LinkExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6476 ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6477 ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/31218 Broken LinkExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6476 ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/6477 ExploitThird Party AdvisoryVDB Entry
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226 Third Party AdvisoryVDB Entry
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226 Third Party AdvisoryVDB Entry