← All CVEs

CVE-2007-2586

high · 9.3

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

9.3
CVSS
14.4%
EPSS (exploit prob.)
96th
EPSS percentile
2007-05-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
ciscoios12.0(1)t
ciscoios12.0(1)t1
ciscoios12.0(1)xe
ciscoios12.0(2)s
ciscoios12.0(2)t
ciscoios12.0(2)t1
ciscoios12.0(2)xe
ciscoios12.0(2)xe1
ciscoios12.0(2)xe3
ciscoios12.0(2)xe4
ciscoios12.0(2a)t1
ciscoios12.0(3)s
ciscoios12.0(3)t
ciscoios12.0(3)t2
ciscoios12.0(3)t3
ciscoios12.0(4)s
ciscoios12.0(4)t
ciscoios12.0(4)xe
ciscoios12.0(4)xe2
ciscoios12.0(5)s
ciscoios12.0(5)t
ciscoios12.0(5)t1
ciscoios12.0(5)xe
ciscoios12.0(5)xe1
ciscoios12.0(5)xe2
ciscoios12.0(5)xe3
ciscoios12.0(5)xe4
ciscoios12.0(5)xe5
ciscoios12.0(5)xe8
ciscoios12.0(5)xk
ciscoios12.0(5)xk1
ciscoios12.0(5)xk2
ciscoios12.0(5)xt1
ciscoios12.0(6)s
ciscoios12.0(6)s1
ciscoios12.0(6)s2
ciscoios12.0(7)s
ciscoios12.0(7)s1
ciscoios12.0(7)t
ciscoios12.0(7)t1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2586