SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-1257

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

HIGH 10.0EPSS 6.81%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
6.81% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cisco/network analysis module · cisco/catalyst 6000 ws-svc-nam-1 · cisco/catalyst 6000 ws-svc-nam-2 · cisco/catalyst 6000 ws-x6380-nam · cisco/catalyst 6500 ws-svc-nam-1 · cisco/catalyst 6500 ws-svc-nam-2 · cisco/catalyst 6500 ws-x6380-nam · cisco/catalyst 7600 ws-svc-nam-1 · cisco/catalyst 7600 ws-svc-nam-2 · cisco/catalyst 7600 ws-x6380-nam
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.