VulnerabilityModified
CVE-2001-0621
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
HIGH 7.5EPSS 1.40%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- cisco/content services switch 11000
- Source
- cve@mitre.org
References
- http://www.ciac.org/ciac/bulletins/l-085.shtml
- http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/1834
- http://www.securityfocus.com/bid/2745
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6557
- http://www.ciac.org/ciac/bulletins/l-085.shtml
- http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/1834
- http://www.securityfocus.com/bid/2745
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6557
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.