CVE-2000-0945
high · 10The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
10
CVSS
72.6%
EPSS (exploit prob.)
99th
EPSS percentile
2000-12-19
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | catalyst_3500_xl | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html
- http://www.osvdb.org/444
- http://www.securityfocus.com/bid/1846
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5415
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html
- http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html
- http://www.osvdb.org/444
- http://www.securityfocus.com/bid/1846
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5415
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2000-0945