9.3

CVE-2001-0537

Exploit

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version11.3
CiscoIos Version11.3aa
CiscoIos Version11.3da
CiscoIos Version11.3db
CiscoIos Version11.3ha
CiscoIos Version11.3ma
CiscoIos Version11.3na
CiscoIos Version11.3t
CiscoIos Version11.3xa
CiscoIos Version12.0
CiscoIos Version12.0da
CiscoIos Version12.0db
CiscoIos Version12.0dc
CiscoIos Version12.0s
CiscoIos Version12.0sc
CiscoIos Version12.0sl
CiscoIos Version12.0st
CiscoIos Version12.0t
CiscoIos Version12.0wc
CiscoIos Version12.0wt
CiscoIos Version12.0xa
CiscoIos Version12.0xb
CiscoIos Version12.0xc
CiscoIos Version12.0xd
CiscoIos Version12.0xe
CiscoIos Version12.0xf
CiscoIos Version12.0xg
CiscoIos Version12.0xh
CiscoIos Version12.0xi
CiscoIos Version12.0xj
CiscoIos Version12.0xl
CiscoIos Version12.0xm
CiscoIos Version12.0xn
CiscoIos Version12.0xp
CiscoIos Version12.0xq
CiscoIos Version12.0xr
CiscoIos Version12.0xs
CiscoIos Version12.0xu
CiscoIos Version12.0xv
CiscoIos Version12.1
CiscoIos Version12.1aa
CiscoIos Version12.1cx
CiscoIos Version12.1da
CiscoIos Version12.1db
CiscoIos Version12.1dc
CiscoIos Version12.1e
CiscoIos Version12.1ec
CiscoIos Version12.1ex
CiscoIos Version12.1ey
CiscoIos Version12.1ez
CiscoIos Version12.1t
CiscoIos Version12.1xa
CiscoIos Version12.1xb
CiscoIos Version12.1xc
CiscoIos Version12.1xd
CiscoIos Version12.1xe
CiscoIos Version12.1xf
CiscoIos Version12.1xg
CiscoIos Version12.1xh
CiscoIos Version12.1xi
CiscoIos Version12.1xj
CiscoIos Version12.1xk
CiscoIos Version12.1xl
CiscoIos Version12.1xm
CiscoIos Version12.1xp
CiscoIos Version12.1xq
CiscoIos Version12.1xr
CiscoIos Version12.1xs
CiscoIos Version12.1xt
CiscoIos Version12.1xu
CiscoIos Version12.1xv
CiscoIos Version12.1xw
CiscoIos Version12.1xx
CiscoIos Version12.1xy
CiscoIos Version12.1xz
CiscoIos Version12.1ya
CiscoIos Version12.1yb
CiscoIos Version12.1yc
CiscoIos Version12.1yd
CiscoIos Version12.1yf
CiscoIos Version12.2
CiscoIos Version12.2t
CiscoIos Version12.2xa
CiscoIos Version12.2xd
CiscoIos Version12.2xe
CiscoIos Version12.2xh
CiscoIos Version12.2xq
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 93.7% 0.998
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.