The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Catalyst_3500_xl | Cisco | * | * |