CVE-2001-0622
The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- cisco/content services switch 11000
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/1848
- http://www.securityfocus.com/bid/2806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6631
- http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/1848
- http://www.securityfocus.com/bid/2806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6631
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.