Sploitus

CVE-2007-2586

1 known exploit for CVE-2007-2586

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

Affected products
Cisco Ios
Cisco Ios
= 12.0\(1\)t, 12.0\(1\)t1, 12.0\(1\)xe, 12.0\(2\)s, 12.0\(2\)t, 12.0\(2\)t1, 12.0\(2\)xe, 12.0\(2\)xe1, 12.0\(2\)xe3, 12.0\(2\)xe4, 12.0\(2a\)t1, 12.0\(3\)s, 12.0\(3\)t, 12.0\(3\)t2, 12.0\(3\)t3, 12.0\(4\)s, 12.0\(4\)t, 12.0\(4\)xe, 12.0\(4\)xe2, 12.0\(5\)s, 12.0\(5\)t, 12.0\(5\)t1, 12.0\(5\)xe, 12.0\(5\)xe1, 12.0\(5\)xe2, 12.0\(5\)xe3, 12.0\(5\)xe4, 12.0\(5\)xe5, 12.0\(5\)xe8, 12.0\(5\)xk, 12.0\(5\)xk1, 12.0\(5\)xk2, 12.0\(5\)xt1, 12.0\(6\)s, 12.0\(6\)s1, 12.0\(6\)s2, 12.0\(7\)s, 12.0\(7\)s1, 12.0\(7\)t, 12.0\(7\)t1
Fix
Available
CVSS 2.0
9.3 HIGH
EPSS
14.4% (96th percentile)
Weakness
CWE-863
NVD status
Modified
Published
2007-05-09
CVE-2007-2586 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-2586

Proof-of-concept code and exploit modules indexed by Sploitus