Oval Definition:oval:org.mitre.oval:def:5036
Revision Date:2008-09-08Version:2
Title:Cisco IOS FTP Server Authentication Bypass Vulnerability
Description:The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
Family:iosClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2007-2586
Platform(s):Cisco IOS
Product(s):
Definition Synopsis
  • IOS vulnerable versions
  • AND NOT IOS vulnerable versions
  • AND config contains: ftp-server enable
  • BACK