CVE-2007-2586
published 2007-05-10CVE-2007-2586: The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
EXPLOIT
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
Affected
380 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Cisco
Multiple Vulnerabilities in the IOS FTP Server
vendor_cisco·2007-05-09·CVSS 10.0
CVE-2007-2586 [CRITICAL] CWE-399 Multiple Vulnerabilities in the IOS FTP Server
Multiple Vulnerabilities in the IOS FTP Server
The Cisco IOS FTP Server feature contains multiple vulnerabilities that
can result in a denial of service (DoS) condition, improper verification of
user credentials, and the ability to retrieve or write any file from the device
filesystem, including the device's saved configuration. This configuration file
may include passwords or other sensitive information.
The IOS FTP Server is an optional service that is disabled by default.
Devices that are not specifically configured to enable the IOS FTP Server
service are unaffected by these vulnerabilities.
This vulnerability does not apply to the IOS FTP Client feature.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070509-iosft
Cisco
Multiple Vulnerabilities in the IOS FTP Server
vendor_cisco
CVE-2007-2586 Multiple Vulnerabilities in the IOS FTP Server
CVE-2007-2586: Multiple Vulnerabilities in the IOS FTP Server
The Cisco IOS FTP Server feature contains multiple vulnerabilities that can result in a denial of service (DoS) condition, improper verification of user credentials, and the ability to retrieve or write any file from the device filesystem, including the device's saved configuration. This configuration file may include passwords or other sensitive information. The IOS FTP Server is an optional service that is disabled by default. Devices that are not specifically configured to enable the IOS FTP Server service are unaffected by these vulnerabilities. This vulnerability does not apply to the IOS FTP Client feature. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-200
GHSA
GHSA-m5c2-384p-37r2: The FTP Server in Cisco IOS 11
ghsa_unreviewed·2022-05-01
CVE-2007-2586 [HIGH] CWE-863 GHSA-m5c2-384p-37r2: The FTP Server in Cisco IOS 11
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
No detection rules found.
No writeups or analysis indexed.
http://seclists.org/bugtraq/2009/Jan/0183.htmlhttp://secunia.com/advisories/25199http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtmlhttp://www.exploit-db.com/exploits/6155http://www.osvdb.org/35334http://www.securityfocus.com/archive/1/494868http://www.securityfocus.com/bid/23885http://www.securitytracker.com/id?1018030http://www.vupen.com/english/advisories/2007/1749https://exchange.xforce.ibmcloud.com/vulnerabilities/34197https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5036http://seclists.org/bugtraq/2009/Jan/0183.htmlhttp://secunia.com/advisories/25199http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtmlhttp://www.exploit-db.com/exploits/6155http://www.osvdb.org/35334http://www.securityfocus.com/archive/1/494868http://www.securityfocus.com/bid/23885http://www.securitytracker.com/id?1018030http://www.vupen.com/english/advisories/2007/1749https://exchange.xforce.ibmcloud.com/vulnerabilities/34197https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5036
2007-05-10
Published