The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
Link | Tags |
---|---|
http://www.osvdb.org/444 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5415 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/1846 | vdb entry patch vendor advisory |