CVE Vulnerabilities

CVE-2007-2586

Incorrect Authorization

Published: May 10, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

Weakness

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Software

NameVendorStart VersionEnd Version
IosCisco12.0(1)t (including)12.0(1)t (including)
IosCisco12.0(1)t1 (including)12.0(1)t1 (including)
IosCisco12.0(1)xe (including)12.0(1)xe (including)
IosCisco12.0(2)s (including)12.0(2)s (including)
IosCisco12.0(2)t (including)12.0(2)t (including)
IosCisco12.0(2)t1 (including)12.0(2)t1 (including)
IosCisco12.0(2)xe (including)12.0(2)xe (including)
IosCisco12.0(2)xe1 (including)12.0(2)xe1 (including)
IosCisco12.0(2)xe3 (including)12.0(2)xe3 (including)
IosCisco12.0(2)xe4 (including)12.0(2)xe4 (including)
IosCisco12.0(2a)t1 (including)12.0(2a)t1 (including)
IosCisco12.0(3)s (including)12.0(3)s (including)
IosCisco12.0(3)t (including)12.0(3)t (including)
IosCisco12.0(3)t2 (including)12.0(3)t2 (including)
IosCisco12.0(3)t3 (including)12.0(3)t3 (including)
IosCisco12.0(4)s (including)12.0(4)s (including)
IosCisco12.0(4)t (including)12.0(4)t (including)
IosCisco12.0(4)xe (including)12.0(4)xe (including)
IosCisco12.0(4)xe2 (including)12.0(4)xe2 (including)
IosCisco12.0(5)s (including)12.0(5)s (including)
IosCisco12.0(5)t (including)12.0(5)t (including)
IosCisco12.0(5)t1 (including)12.0(5)t1 (including)
IosCisco12.0(5)xe (including)12.0(5)xe (including)
IosCisco12.0(5)xe1 (including)12.0(5)xe1 (including)
IosCisco12.0(5)xe2 (including)12.0(5)xe2 (including)
IosCisco12.0(5)xe3 (including)12.0(5)xe3 (including)
IosCisco12.0(5)xe4 (including)12.0(5)xe4 (including)
IosCisco12.0(5)xe5 (including)12.0(5)xe5 (including)
IosCisco12.0(5)xe8 (including)12.0(5)xe8 (including)
IosCisco12.0(5)xk (including)12.0(5)xk (including)
IosCisco12.0(5)xk1 (including)12.0(5)xk1 (including)
IosCisco12.0(5)xk2 (including)12.0(5)xk2 (including)
IosCisco12.0(5)xt1 (including)12.0(5)xt1 (including)
IosCisco12.0(6)s (including)12.0(6)s (including)
IosCisco12.0(6)s1 (including)12.0(6)s1 (including)
IosCisco12.0(6)s2 (including)12.0(6)s2 (including)
IosCisco12.0(7)s (including)12.0(7)s (including)
IosCisco12.0(7)s1 (including)12.0(7)s1 (including)
IosCisco12.0(7)t (including)12.0(7)t (including)
IosCisco12.0(7)t1 (including)12.0(7)t1 (including)
IosCisco12.0(7)t2 (including)12.0(7)t2 (including)
IosCisco12.0(7)t3 (including)12.0(7)t3 (including)
IosCisco12.0(7)xk (including)12.0(7)xk (including)
IosCisco12.0(7)xk1 (including)12.0(7)xk1 (including)
IosCisco12.0(7)xk2 (including)12.0(7)xk2 (including)
IosCisco12.0(7)xk3 (including)12.0(7)xk3 (including)
IosCisco12.0(8)s (including)12.0(8)s (including)
IosCisco12.0(8)s1 (including)12.0(8)s1 (including)
IosCisco12.0(9)s (including)12.0(9)s (including)
IosCisco12.0(9)s8 (including)12.0(9)s8 (including)
IosCisco12.0(9)st (including)12.0(9)st (including)
IosCisco12.0(10)s (including)12.0(10)s (including)
IosCisco12.0(10)s1 (including)12.0(10)s1 (including)
IosCisco12.0(10)s2 (including)12.0(10)s2 (including)
IosCisco12.0(10)s3 (including)12.0(10)s3 (including)
IosCisco12.0(10)s3b (including)12.0(10)s3b (including)
IosCisco12.0(10)s4 (including)12.0(10)s4 (including)
IosCisco12.0(10)s5 (including)12.0(10)s5 (including)
IosCisco12.0(10)s6 (including)12.0(10)s6 (including)
IosCisco12.0(10)s7 (including)12.0(10)s7 (including)
IosCisco12.0(10)s8 (including)12.0(10)s8 (including)
IosCisco12.0(10)st (including)12.0(10)st (including)
IosCisco12.0(10)st1 (including)12.0(10)st1 (including)
IosCisco12.0(10)st2 (including)12.0(10)st2 (including)
IosCisco12.0(11)s (including)12.0(11)s (including)
IosCisco12.0(11)s1 (including)12.0(11)s1 (including)
IosCisco12.0(11)s2 (including)12.0(11)s2 (including)
IosCisco12.0(11)s3 (including)12.0(11)s3 (including)
IosCisco12.0(11)s4 (including)12.0(11)s4 (including)
IosCisco12.0(11)s5 (including)12.0(11)s5 (including)
IosCisco12.0(11)s6 (including)12.0(11)s6 (including)
IosCisco12.0(11)st (including)12.0(11)st (including)
IosCisco12.0(11)st1 (including)12.0(11)st1 (including)
IosCisco12.0(11)st2 (including)12.0(11)st2 (including)
IosCisco12.0(11)st3 (including)12.0(11)st3 (including)
IosCisco12.0(11)st4 (including)12.0(11)st4 (including)
IosCisco12.0(28)s4a (including)12.0(28)s4a (including)
IosCisco12.0(31)sz2 (including)12.0(31)sz2 (including)
IosCisco12.1(3)xi (including)12.1(3)xi (including)
IosCisco12.1(5)xm (including)12.1(5)xm (including)
IosCisco12.1(5)xm1 (including)12.1(5)xm1 (including)
IosCisco12.1(5)xm2 (including)12.1(5)xm2 (including)
IosCisco12.1(5)xm3 (including)12.1(5)xm3 (including)
IosCisco12.1(5)xm4 (including)12.1(5)xm4 (including)
IosCisco12.1(5)xm5 (including)12.1(5)xm5 (including)
IosCisco12.1(5)xm7 (including)12.1(5)xm7 (including)
IosCisco12.1(5)xm8 (including)12.1(5)xm8 (including)
IosCisco12.1(5c)ex (including)12.1(5c)ex (including)
IosCisco12.1(5c)ex1 (including)12.1(5c)ex1 (including)
IosCisco12.1(6)ex (including)12.1(6)ex (including)
IosCisco12.1(8b)ex4 (including)12.1(8b)ex4 (including)
IosCisco12.1(9)ex (including)12.1(9)ex (including)
IosCisco12.2(8)zb (including)12.2(8)zb (including)
IosCisco12.2(9)yo (including)12.2(9)yo (including)
IosCisco12.2(9)yo1 (including)12.2(9)yo1 (including)
IosCisco12.2(9)yo2 (including)12.2(9)yo2 (including)
IosCisco12.2(9)yo3 (including)12.2(9)yo3 (including)
IosCisco12.2(9)yo4 (including)12.2(9)yo4 (including)
IosCisco12.2(11)yz (including)12.2(11)yz (including)
IosCisco12.2(11)yz1 (including)12.2(11)yz1 (including)
IosCisco12.2(11)yz2 (including)12.2(11)yz2 (including)
IosCisco12.2(11)yz3 (including)12.2(11)yz3 (including)
IosCisco12.2(12b)m1 (including)12.2(12b)m1 (including)
IosCisco12.2(12h)m1 (including)12.2(12h)m1 (including)
IosCisco12.2(13)zf (including)12.2(13)zf (including)
IosCisco12.2(13)zf1 (including)12.2(13)zf1 (including)
IosCisco12.2(13)zf2 (including)12.2(13)zf2 (including)
IosCisco12.2(13)zh (including)12.2(13)zh (including)
IosCisco12.2(13)zh1 (including)12.2(13)zh1 (including)
IosCisco12.2(13)zh2 (including)12.2(13)zh2 (including)
IosCisco12.2(13)zh3 (including)12.2(13)zh3 (including)
IosCisco12.2(13)zh4 (including)12.2(13)zh4 (including)
IosCisco12.2(13)zh5 (including)12.2(13)zh5 (including)
IosCisco12.2(13b)m1 (including)12.2(13b)m1 (including)
IosCisco12.2(13b)m2 (including)12.2(13b)m2 (including)
IosCisco12.2(14)sz (including)12.2(14)sz (including)
IosCisco12.2(14)sz1 (including)12.2(14)sz1 (including)
IosCisco12.2(14)sz2 (including)12.2(14)sz2 (including)
IosCisco12.2(14)sz3 (including)12.2(14)sz3 (including)
IosCisco12.2(14)sz4 (including)12.2(14)sz4 (including)
IosCisco12.2(14)sz5 (including)12.2(14)sz5 (including)
IosCisco12.2(14)sz6 (including)12.2(14)sz6 (including)
IosCisco12.2(15)zj (including)12.2(15)zj (including)
IosCisco12.2(15)zj1 (including)12.2(15)zj1 (including)
IosCisco12.2(15)zj2 (including)12.2(15)zj2 (including)
IosCisco12.2(15)zj3 (including)12.2(15)zj3 (including)
IosCisco12.2(15)zj4 (including)12.2(15)zj4 (including)
IosCisco12.2(15)zj5 (including)12.2(15)zj5 (including)
IosCisco12.2(15)zl (including)12.2(15)zl (including)
IosCisco12.2(15)zl1 (including)12.2(15)zl1 (including)
IosCisco12.2(15)zn (including)12.2(15)zn (including)
IosCisco12.2(18)s (including)12.2(18)s (including)
IosCisco12.2(18)s1 (including)12.2(18)s1 (including)
IosCisco12.2(18)s2 (including)12.2(18)s2 (including)
IosCisco12.2(18)s3 (including)12.2(18)s3 (including)
IosCisco12.2(18)s4 (including)12.2(18)s4 (including)
IosCisco12.2(20)s (including)12.2(20)s (including)
IosCisco12.2(20)s1 (including)12.2(20)s1 (including)
IosCisco12.2(20)s2 (including)12.2(20)s2 (including)
IosCisco12.2(20)s2a (including)12.2(20)s2a (including)
IosCisco12.2(20)s3 (including)12.2(20)s3 (including)
IosCisco12.2(20)s4 (including)12.2(20)s4 (including)
IosCisco12.2(20)s4a (including)12.2(20)s4a (including)
IosCisco12.2(20)s5 (including)12.2(20)s5 (including)
IosCisco12.2(20)s6 (including)12.2(20)s6 (including)
IosCisco12.2(22)s (including)12.2(22)s (including)
IosCisco12.2(25)s (including)12.2(25)s (including)
IosCisco12.2(25)s1 (including)12.2(25)s1 (including)
IosCisco12.2(25)s2 (including)12.2(25)s2 (including)
IosCisco12.2(25)se (including)12.2(25)se (including)
IosCisco12.3(1a)b (including)12.3(1a)b (including)
IosCisco12.3(2)ja3 (including)12.3(2)ja3 (including)
IosCisco12.3(2)ja4 (including)12.3(2)ja4 (including)
IosCisco12.3(2)t (including)12.3(2)t (including)
IosCisco12.3(2)t1 (including)12.3(2)t1 (including)
IosCisco12.3(2)t2 (including)12.3(2)t2 (including)
IosCisco12.3(2)t3 (including)12.3(2)t3 (including)
IosCisco12.3(2)t4 (including)12.3(2)t4 (including)
IosCisco12.3(2)t5 (including)12.3(2)t5 (including)
IosCisco12.3(2)t6 (including)12.3(2)t6 (including)
IosCisco12.3(2)t7 (including)12.3(2)t7 (including)
IosCisco12.3(2)t8 (including)12.3(2)t8 (including)
IosCisco12.3(2)t9 (including)12.3(2)t9 (including)
IosCisco12.3(2)xa (including)12.3(2)xa (including)
IosCisco12.3(2)xa1 (including)12.3(2)xa1 (including)
IosCisco12.3(2)xa2 (including)12.3(2)xa2 (including)
IosCisco12.3(2)xa3 (including)12.3(2)xa3 (including)
IosCisco12.3(2)xa4 (including)12.3(2)xa4 (including)
IosCisco12.3(2)xa5 (including)12.3(2)xa5 (including)
IosCisco12.3(2)xc (including)12.3(2)xc (including)
IosCisco12.3(2)xc1 (including)12.3(2)xc1 (including)
IosCisco12.3(2)xc2 (including)12.3(2)xc2 (including)
IosCisco12.3(2)xe (including)12.3(2)xe (including)
IosCisco12.3(2)xe1 (including)12.3(2)xe1 (including)
IosCisco12.3(2)xe2 (including)12.3(2)xe2 (including)
IosCisco12.3(2)xe3 (including)12.3(2)xe3 (including)
IosCisco12.3(2)xe4 (including)12.3(2)xe4 (including)
IosCisco12.3(2)xf (including)12.3(2)xf (including)
IosCisco12.3(3)b (including)12.3(3)b (including)
IosCisco12.3(3)b1 (including)12.3(3)b1 (including)
IosCisco12.3(4)t (including)12.3(4)t (including)
IosCisco12.3(4)t1 (including)12.3(4)t1 (including)
IosCisco12.3(4)t2 (including)12.3(4)t2 (including)
IosCisco12.3(4)t3 (including)12.3(4)t3 (including)
IosCisco12.3(4)t4 (including)12.3(4)t4 (including)
IosCisco12.3(4)t5 (including)12.3(4)t5 (including)
IosCisco12.3(4)t6 (including)12.3(4)t6 (including)
IosCisco12.3(4)t7 (including)12.3(4)t7 (including)
IosCisco12.3(4)t8 (including)12.3(4)t8 (including)
IosCisco12.3(4)t9 (including)12.3(4)t9 (including)
IosCisco12.3(4)t10 (including)12.3(4)t10 (including)
IosCisco12.3(4)t11 (including)12.3(4)t11 (including)
IosCisco12.3(4)tpc11a (including)12.3(4)tpc11a (including)
IosCisco12.3(4)xd (including)12.3(4)xd (including)
IosCisco12.3(4)xd1 (including)12.3(4)xd1 (including)
IosCisco12.3(4)xd2 (including)12.3(4)xd2 (including)
IosCisco12.3(4)xd3 (including)12.3(4)xd3 (including)
IosCisco12.3(4)xd4 (including)12.3(4)xd4 (including)
IosCisco12.3(4)xg (including)12.3(4)xg (including)
IosCisco12.3(4)xg1 (including)12.3(4)xg1 (including)
IosCisco12.3(4)xg2 (including)12.3(4)xg2 (including)
IosCisco12.3(4)xg3 (including)12.3(4)xg3 (including)
IosCisco12.3(4)xg4 (including)12.3(4)xg4 (including)
IosCisco12.3(4)xg5 (including)12.3(4)xg5 (including)
IosCisco12.3(4)xh (including)12.3(4)xh (including)
IosCisco12.3(4)xh1 (including)12.3(4)xh1 (including)
IosCisco12.3(4)xk (including)12.3(4)xk (including)
IosCisco12.3(4)xk1 (including)12.3(4)xk1 (including)
IosCisco12.3(4)xk2 (including)12.3(4)xk2 (including)
IosCisco12.3(4)xk3 (including)12.3(4)xk3 (including)
IosCisco12.3(4)xk4 (including)12.3(4)xk4 (including)
IosCisco12.3(4)xq (including)12.3(4)xq (including)
IosCisco12.3(4)xq1 (including)12.3(4)xq1 (including)
IosCisco12.3(4)ye (including)12.3(4)ye (including)
IosCisco12.3(4)ye1 (including)12.3(4)ye1 (including)
IosCisco12.3(5a)b (including)12.3(5a)b (including)
IosCisco12.3(5a)b0a (including)12.3(5a)b0a (including)
IosCisco12.3(5a)b1 (including)12.3(5a)b1 (including)
IosCisco12.3(5a)b2 (including)12.3(5a)b2 (including)
IosCisco12.3(5a)b3 (including)12.3(5a)b3 (including)
IosCisco12.3(5a)b4 (including)12.3(5a)b4 (including)
IosCisco12.3(5a)b5 (including)12.3(5a)b5 (including)
IosCisco12.3(7)jx9 (including)12.3(7)jx9 (including)
IosCisco12.3(7)t (including)12.3(7)t (including)
IosCisco12.3(7)t1 (including)12.3(7)t1 (including)
IosCisco12.3(7)t2 (including)12.3(7)t2 (including)
IosCisco12.3(7)t3 (including)12.3(7)t3 (including)
IosCisco12.3(7)t4 (including)12.3(7)t4 (including)
IosCisco12.3(7)t6 (including)12.3(7)t6 (including)
IosCisco12.3(7)t7 (including)12.3(7)t7 (including)
IosCisco12.3(7)t8 (including)12.3(7)t8 (including)
IosCisco12.3(7)t9 (including)12.3(7)t9 (including)
IosCisco12.3(7)t10 (including)12.3(7)t10 (including)
IosCisco12.3(7)t11 (including)12.3(7)t11 (including)
IosCisco12.3(7)t12 (including)12.3(7)t12 (including)
IosCisco12.3(7)xi3a (including)12.3(7)xi3a (including)
IosCisco12.3(7)xl (including)12.3(7)xl (including)
IosCisco12.3(7)xr (including)12.3(7)xr (including)
IosCisco12.3(7)xr1 (including)12.3(7)xr1 (including)
IosCisco12.3(7)xr2 (including)12.3(7)xr2 (including)
IosCisco12.3(7)xr3 (including)12.3(7)xr3 (including)
IosCisco12.3(7)xr4 (including)12.3(7)xr4 (including)
IosCisco12.3(7)xr5 (including)12.3(7)xr5 (including)
IosCisco12.3(7)xr6 (including)12.3(7)xr6 (including)
IosCisco12.3(7)xs (including)12.3(7)xs (including)
IosCisco12.3(7)xs1 (including)12.3(7)xs1 (including)
IosCisco12.3(7)xs2 (including)12.3(7)xs2 (including)
IosCisco12.3(8)jk (including)12.3(8)jk (including)
IosCisco12.3(8)t (including)12.3(8)t (including)
IosCisco12.3(8)t1 (including)12.3(8)t1 (including)
IosCisco12.3(8)t2 (including)12.3(8)t2 (including)
IosCisco12.3(8)t3 (including)12.3(8)t3 (including)
IosCisco12.3(8)t4 (including)12.3(8)t4 (including)
IosCisco12.3(8)t5 (including)12.3(8)t5 (including)
IosCisco12.3(8)t6 (including)12.3(8)t6 (including)
IosCisco12.3(8)t7 (including)12.3(8)t7 (including)
IosCisco12.3(8)t8 (including)12.3(8)t8 (including)
IosCisco12.3(8)t9 (including)12.3(8)t9 (including)
IosCisco12.3(8)t10 (including)12.3(8)t10 (including)
IosCisco12.3(8)t11 (including)12.3(8)t11 (including)
IosCisco12.3(8)xx (including)12.3(8)xx (including)
IosCisco12.3(8)xx1 (including)12.3(8)xx1 (including)
IosCisco12.3(8)xx2 (including)12.3(8)xx2 (including)
IosCisco12.3(8)xx2a (including)12.3(8)xx2a (including)
IosCisco12.3(8)xx2b (including)12.3(8)xx2b (including)
IosCisco12.3(8)xx2c (including)12.3(8)xx2c (including)
IosCisco12.3(8)ya (including)12.3(8)ya (including)
IosCisco12.3(8)ya1 (including)12.3(8)ya1 (including)
IosCisco12.3(8)yc (including)12.3(8)yc (including)
IosCisco12.3(8)yc1 (including)12.3(8)yc1 (including)
IosCisco12.3(8)yc2 (including)12.3(8)yc2 (including)
IosCisco12.3(8)yc3 (including)12.3(8)yc3 (including)
IosCisco12.3(8)yd (including)12.3(8)yd (including)
IosCisco12.3(8)yd1 (including)12.3(8)yd1 (including)
IosCisco12.3(8)yg (including)12.3(8)yg (including)
IosCisco12.3(8)yg1 (including)12.3(8)yg1 (including)
IosCisco12.3(8)yg2 (including)12.3(8)yg2 (including)
IosCisco12.3(8)yg3 (including)12.3(8)yg3 (including)
IosCisco12.3(8)yg4 (including)12.3(8)yg4 (including)
IosCisco12.3(8)yg5 (including)12.3(8)yg5 (including)
IosCisco12.3(8)yh (including)12.3(8)yh (including)
IosCisco12.3(8)yi (including)12.3(8)yi (including)
IosCisco12.3(8)yi1 (including)12.3(8)yi1 (including)
IosCisco12.3(8)yi2 (including)12.3(8)yi2 (including)
IosCisco12.3(8)yi3 (including)12.3(8)yi3 (including)
IosCisco12.3(8)za (including)12.3(8)za (including)
IosCisco12.3(9)m0 (including)12.3(9)m0 (including)
IosCisco12.3(9)m1 (including)12.3(9)m1 (including)
IosCisco12.3(10a)m0 (including)12.3(10a)m0 (including)
IosCisco12.3(11)ja2 (including)12.3(11)ja2 (including)
IosCisco12.3(11)jx (including)12.3(11)jx (including)
IosCisco12.3(11)jx1 (including)12.3(11)jx1 (including)
IosCisco12.3(11)t (including)12.3(11)t (including)
IosCisco12.3(11)t1 (including)12.3(11)t1 (including)
IosCisco12.3(11)t2 (including)12.3(11)t2 (including)
IosCisco12.3(11)t3 (including)12.3(11)t3 (including)
IosCisco12.3(11)t4 (including)12.3(11)t4 (including)
IosCisco12.3(11)t5 (including)12.3(11)t5 (including)
IosCisco12.3(11)t6 (including)12.3(11)t6 (including)
IosCisco12.3(11)t7 (including)12.3(11)t7 (including)
IosCisco12.3(11)t8 (including)12.3(11)t8 (including)
IosCisco12.3(11)t9 (including)12.3(11)t9 (including)
IosCisco12.3(11)t10 (including)12.3(11)t10 (including)
IosCisco12.3(11)t11 (including)12.3(11)t11 (including)
IosCisco12.3(11)to3 (including)12.3(11)to3 (including)
IosCisco12.3(11)xl (including)12.3(11)xl (including)
IosCisco12.3(11)xl1 (including)12.3(11)xl1 (including)
IosCisco12.3(11)xl2 (including)12.3(11)xl2 (including)
IosCisco12.3(11)xl3 (including)12.3(11)xl3 (including)
IosCisco12.3(11)yf2 (including)12.3(11)yf2 (including)
IosCisco12.3(11)yk (including)12.3(11)yk (including)
IosCisco12.3(11)yk1 (including)12.3(11)yk1 (including)
IosCisco12.3(11)yk2 (including)12.3(11)yk2 (including)
IosCisco12.3(11)yl (including)12.3(11)yl (including)
IosCisco12.3(11)yl1 (including)12.3(11)yl1 (including)
IosCisco12.3(11)yl2 (including)12.3(11)yl2 (including)
IosCisco12.3(11)ys (including)12.3(11)ys (including)
IosCisco12.3(11)ys1 (including)12.3(11)ys1 (including)
IosCisco12.3(11)yz (including)12.3(11)yz (including)
IosCisco12.3(11)yz1 (including)12.3(11)yz1 (including)
IosCisco12.3(11)zb (including)12.3(11)zb (including)
IosCisco12.3(11)zb1 (including)12.3(11)zb1 (including)
IosCisco12.3(14)t (including)12.3(14)t (including)
IosCisco12.3(14)t1 (including)12.3(14)t1 (including)
IosCisco12.3(14)t2 (including)12.3(14)t2 (including)
IosCisco12.3(14)t3 (including)12.3(14)t3 (including)
IosCisco12.3(14)t4 (including)12.3(14)t4 (including)
IosCisco12.3(14)t5 (including)12.3(14)t5 (including)
IosCisco12.3(14)t6 (including)12.3(14)t6 (including)
IosCisco12.3(14)t7 (including)12.3(14)t7 (including)
IosCisco12.3(14)ym2 (including)12.3(14)ym2 (including)
IosCisco12.3(14)ym3 (including)12.3(14)ym3 (including)
IosCisco12.3(14)ym4 (including)12.3(14)ym4 (including)
IosCisco12.3(14)ym5 (including)12.3(14)ym5 (including)
IosCisco12.3(14)ym6 (including)12.3(14)ym6 (including)
IosCisco12.3(14)ym7 (including)12.3(14)ym7 (including)
IosCisco12.3(14)ym8 (including)12.3(14)ym8 (including)
IosCisco12.3(14)ym9 (including)12.3(14)ym9 (including)
IosCisco12.3(14)yt (including)12.3(14)yt (including)
IosCisco12.3(14)yt1 (including)12.3(14)yt1 (including)
IosCisco12.4(2)t (including)12.4(2)t (including)
IosCisco12.4(2)t1 (including)12.4(2)t1 (including)
IosCisco12.4(2)t2 (including)12.4(2)t2 (including)
IosCisco12.4(2)t3 (including)12.4(2)t3 (including)
IosCisco12.4(2)t4 (including)12.4(2)t4 (including)
IosCisco12.4(2)t5 (including)12.4(2)t5 (including)
IosCisco12.4(2)xa (including)12.4(2)xa (including)
IosCisco12.4(2)xa1 (including)12.4(2)xa1 (including)
IosCisco12.4(2)xa2 (including)12.4(2)xa2 (including)
IosCisco12.4(4)t (including)12.4(4)t (including)
IosCisco12.4(4)t1 (including)12.4(4)t1 (including)
IosCisco12.4(4)t2 (including)12.4(4)t2 (including)
IosCisco12.4(4)t3 (including)12.4(4)t3 (including)
IosCisco12.4(4)t4 (including)12.4(4)t4 (including)
IosCisco12.4(4)t5 (including)12.4(4)t5 (including)
IosCisco12.4(4)xc (including)12.4(4)xc (including)
IosCisco12.4(4)xc1 (including)12.4(4)xc1 (including)
IosCisco12.4(4)xc2 (including)12.4(4)xc2 (including)
IosCisco12.4(4)xc3 (including)12.4(4)xc3 (including)
IosCisco12.4(4)xc4 (including)12.4(4)xc4 (including)
IosCisco12.4(4)xc5 (including)12.4(4)xc5 (including)
IosCisco12.4(4)xd (including)12.4(4)xd (including)
IosCisco12.4(4)xd1 (including)12.4(4)xd1 (including)
IosCisco12.4(4)xd2 (including)12.4(4)xd2 (including)
IosCisco12.4(4)xd3 (including)12.4(4)xd3 (including)
IosCisco12.4(5a)m0 (including)12.4(5a)m0 (including)
IosCisco12.4(6)t (including)12.4(6)t (including)
IosCisco12.4(6)t1 (including)12.4(6)t1 (including)
IosCisco12.4(6)t2 (including)12.4(6)t2 (including)
IosCisco12.4(6)t3 (including)12.4(6)t3 (including)
IosCisco12.4(6)t4 (including)12.4(6)t4 (including)
IosCisco12.4(6)t5 (including)12.4(6)t5 (including)
IosCisco12.4(6)xe (including)12.4(6)xe (including)
IosCisco12.4(6)xe1 (including)12.4(6)xe1 (including)
IosCisco12.4(6)xe2 (including)12.4(6)xe2 (including)
IosCisco12.4(9)t (including)12.4(9)t (including)
IosCisco12.4(9)t0a (including)12.4(9)t0a (including)
IosCisco12.4(9)t1 (including)12.4(9)t1 (including)
IosCisco12.4(11)sw (including)12.4(11)sw (including)
IosCisco12.4(11)sw1 (including)12.4(11)sw1 (including)

Potential Mitigations

  • Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries.
  • Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
  • For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
  • One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.

References