← All CVEs

CVE-2001-0537

high · 9.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

9.3
CVSS
68.5%
EPSS (exploit prob.)
99th
EPSS percentile
2001-07-21
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
ciscoios11.3
ciscoios11.3aa
ciscoios11.3da
ciscoios11.3db
ciscoios11.3ha
ciscoios11.3ma
ciscoios11.3na
ciscoios11.3t
ciscoios11.3xa
ciscoios12.0
ciscoios12.0(5)xk
ciscoios12.0(7)xk
ciscoios12.0(10)w5(18g)
ciscoios12.0(14)w5(20)
ciscoios12.0da
ciscoios12.0db
ciscoios12.0dc
ciscoios12.0s
ciscoios12.0sc
ciscoios12.0sl
ciscoios12.0st
ciscoios12.0t
ciscoios12.0wc
ciscoios12.0wt
ciscoios12.0xa
ciscoios12.0xb
ciscoios12.0xc
ciscoios12.0xd
ciscoios12.0xe
ciscoios12.0xf
ciscoios12.0xg
ciscoios12.0xh
ciscoios12.0xi
ciscoios12.0xj
ciscoios12.0xl
ciscoios12.0xm
ciscoios12.0xn
ciscoios12.0xp
ciscoios12.0xq
ciscoios12.0xr

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2001-0537