Cisco Cbos vulnerabilities

9 known vulnerabilities affecting cisco/cbos.

Total CVEs
9
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6LOW1

Vulnerabilities

Page 1 of 1
CVE-2007-4430MEDIUMCVSS 5.0PoCv12.1v12.22007-08-20
CVE-2007-4430 [MEDIUM] CWE-20 CVE-2007-4430: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
nvd
CVE-2002-0886MEDIUMCVSS 5.0PoCv2.0.1v2.1.0+19 more2002-10-04
CVE-2002-0886 [MEDIUM] CVE-2002-0886: Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of se Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.
nvd
CVE-2001-0751HIGHCVSS 7.5PoC≤ 2.3.82001-10-18
CVE-2001-0751 [HIGH] CVE-2001-0751: Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbe Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections.
nvd
CVE-2001-0753HIGHCVSS 7.5≤ 2.3.82001-10-18
CVE-2001-0753 [HIGH] CVE-2001-0753: Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NV Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.
nvd
CVE-2001-0754MEDIUMCVSS 5.0≤ 2.3.82001-10-18
CVE-2001-0754 [MEDIUM] CVE-2001-0754: Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of la Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets.
nvd
CVE-2001-0752MEDIUMCVSS 5.0≤ 2.3.82001-10-18
CVE-2001-0752 [MEDIUM] CVE-2001-0752: Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO R Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set.
nvd
CVE-2001-1064MEDIUMCVSS 5.0PoC≤ 2.4.2apv2.0.1+13 more2001-08-31
CVE-2001-1064 [MEDIUM] CVE-2001-1064: Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denia Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.
nvd
CVE-2001-1065MEDIUMCVSS 5.0≤ 2.4.2apv2.0.12001-08-31
CVE-2001-1065 [MEDIUM] CVE-2001-1065: Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.
nvd
CVE-2001-0444LOWCVSS 2.1v2.3.053v2.4.12001-07-02
CVE-2001-0444 [LOW] CVE-2001-0444: Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the ne Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.
nvd
Cisco Cbos vulnerabilities | cvebase