Vulnerability Name:

CVE-2007-2586 (CCN-34197)

Assigned:2007-05-09
Published:2007-05-09
Updated:2023-05-09
Summary:
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-2586

Source: cve@mitre.org
Type: Issue Tracking, Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: SA25199
Cisco IOS FTP Server Multiple Vulnerabilities

Source: CCN
Type: SECTRACK ID: 1018030
Cisco IOS FTP Server Lets Remote Users Read and Write Files and Denial of Service

Source: cve@mitre.org
Type: Not Applicable
cve@mitre.org

Source: CCN
Type: cisco-sa-20070509-iosftp
Cisco Security Advisory: Multiple Vulnerabilities in the IOS FTP Server

Source: cve@mitre.org
Type: Exploit, Third Party Advisory, VDB Entry
cve@mitre.org

Source: CCN
Type: OSVDB ID: 35334
Cisco IOS FTP Server User Credential Handling Remote Overflow

Source: cve@mitre.org
Type: Broken Link, Third Party Advisory, VDB Entry
cve@mitre.org

Source: CCN
Type: BID-23885
Cisco IOS FTP Server Multiple Vulnerabilities

Source: cve@mitre.org
Type: Broken Link, Exploit, Third Party Advisory, VDB Entry
cve@mitre.org

Source: cve@mitre.org
Type: Broken Link, Third Party Advisory, VDB Entry
cve@mitre.org

Source: cve@mitre.org
Type: Permissions Required, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory, VDB Entry
cve@mitre.org

Source: XF
Type: UNKNOWN
cisco-ios-ftp-unauthorized-access(34197)

Source: cve@mitre.org
Type: Broken Link, Third Party Advisory
cve@mitre.org

Vulnerability Name:

CVE-2007-2586 (CCN-44146)

Assigned:2007-05-09
Published:2008-07-29
Updated:2008-07-29
Summary:Multiple Cisco devices running certain versions of IOS are vulnerable to a buffer overflow in the FTP service. By sending an overly long APPE, HELP, RNFR, RNTO, STOR, STOU, SITE, DELE, MKD, or RMD command to the IOS FTP service, a remote attacker could overflow a buffer and execute arbitrary code on the affected device.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Jul 29 2008 - 04:37:01 CDT
Remote Cisco IOS FTP server exploit

Source: MITRE
Type: CNA
CVE-2007-2586

Source: CCN
Type: SA25199
Cisco IOS FTP Server Multiple Vulnerabilities

Source: CCN
Type: SECTRACK ID: 1018030
Cisco IOS FTP Server Lets Remote Users Read and Write Files and Denial of Service

Source: CCN
Type: Cisco Document ID: 91476
Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of Multiple Vulnerabilities in the IOS FTP Server

Source: CCN
Type: cisco-sa-20070509-iosftp
Cisco Security Advisory: Multiple Vulnerabilities in the IOS FTP Server

Source: CCN
Type: OSVDB ID: 35334
Cisco IOS FTP Server User Credential Handling Remote Overflow

Source: CCN
Type: BID-23885
Cisco IOS FTP Server Multiple Vulnerabilities

Source: XF
Type: UNKNOWN
cisco-ios-ftp-multiple-bo(44146)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:cisco:ios:12.0:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.1t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.1:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0wc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.1xm:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2zj:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2zl:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0xc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3b:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2zf:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2zh:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2zn:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xa:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xe:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xf:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xg:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xh:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xk:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xq:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xr:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xs:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3xx:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3ya:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yg:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yh:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xa:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2xg:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yi:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yk:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3ys:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yt:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3tpc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xa:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.0xk:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3ym:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3yz:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4sw:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xe:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5036
    V
    Cisco IOS FTP Server Authentication Bypass Vulnerability
    2008-09-08
    BACK
    cisco ios 12.0
    cisco ios 12.1t
    cisco ios 12.0t
    cisco ios 12.1
    cisco ios 12.2t
    cisco ios 12.2
    cisco ios 12.0wc
    cisco ios 12.1xm
    cisco ios 12.2zj
    cisco ios 12.2zl
    cisco ios 12.0xc
    cisco ios 12.3b
    cisco ios 12.3t
    cisco ios 12.2zf
    cisco ios 12.2zh
    cisco ios 12.2zn
    cisco ios 12.3xa
    cisco ios 12.3xc
    cisco ios 12.3xe
    cisco ios 12.3xd
    cisco ios 12.3xf
    cisco ios 12.3xg
    cisco ios 12.3xh
    cisco ios 12.3xk
    cisco ios 12.3xq
    cisco ios 12.3xr
    cisco ios 12.3xs
    cisco ios 12.3xx
    cisco ios 12.3ya
    cisco ios 12.3yd
    cisco ios 12.3yg
    cisco ios 12.3yh
    cisco ios 12.2xa
    cisco ios 12.2xg
    cisco ios 12.3yi
    cisco ios 12.3yk
    cisco ios 12.3ys
    cisco ios 12.3
    cisco ios 12.3yt
    cisco ios 12.4t
    cisco ios 12.3tpc
    cisco ios 12.4xa
    cisco ios 12.0xk
    cisco ios 12.3ym
    cisco ios 12.3yz
    cisco ios 12.4sw
    cisco ios 12.4xc
    cisco ios 12.4xd
    cisco ios 12.4xe