CVE Vulnerabilities

CVE-2009-0637

Published: Mar 27, 2009 | Modified: Aug 25, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.

Affected Software

Name Vendor Start Version End Version
Ios Cisco 12.2 (including) 12.2 (including)
Ios Cisco 12.2b (including) 12.2b (including)
Ios Cisco 12.2bc (including) 12.2bc (including)
Ios Cisco 12.2bw (including) 12.2bw (including)
Ios Cisco 12.2bx (including) 12.2bx (including)
Ios Cisco 12.2by (including) 12.2by (including)
Ios Cisco 12.2bz (including) 12.2bz (including)
Ios Cisco 12.2ca (including) 12.2ca (including)
Ios Cisco 12.2cx (including) 12.2cx (including)
Ios Cisco 12.2cy (including) 12.2cy (including)
Ios Cisco 12.2cz (including) 12.2cz (including)
Ios Cisco 12.2da (including) 12.2da (including)
Ios Cisco 12.2dd (including) 12.2dd (including)
Ios Cisco 12.2dx (including) 12.2dx (including)
Ios Cisco 12.2ew (including) 12.2ew (including)
Ios Cisco 12.2ewa (including) 12.2ewa (including)
Ios Cisco 12.2ex (including) 12.2ex (including)
Ios Cisco 12.2ey (including) 12.2ey (including)
Ios Cisco 12.2ez (including) 12.2ez (including)
Ios Cisco 12.2fx (including) 12.2fx (including)
Ios Cisco 12.2fy (including) 12.2fy (including)
Ios Cisco 12.2fz (including) 12.2fz (including)
Ios Cisco 12.2irb (including) 12.2irb (including)
Ios Cisco 12.2ixa (including) 12.2ixa (including)
Ios Cisco 12.2ixb (including) 12.2ixb (including)
Ios Cisco 12.2ixc (including) 12.2ixc (including)
Ios Cisco 12.2ixd (including) 12.2ixd (including)
Ios Cisco 12.2ixe (including) 12.2ixe (including)
Ios Cisco 12.2ixf (including) 12.2ixf (including)
Ios Cisco 12.2ixg (including) 12.2ixg (including)
Ios Cisco 12.2ja (including) 12.2ja (including)
Ios Cisco 12.2jk (including) 12.2jk (including)
Ios Cisco 12.2l (including) 12.2l (including)
Ios Cisco 12.2mb (including) 12.2mb (including)
Ios Cisco 12.2mc (including) 12.2mc (including)
Ios Cisco 12.2rc (including) 12.2rc (including)
Ios Cisco 12.2s (including) 12.2s (including)
Ios Cisco 12.2sb (including) 12.2sb (including)
Ios Cisco 12.2sbc (including) 12.2sbc (including)
Ios Cisco 12.2sca (including) 12.2sca (including)
Ios Cisco 12.2sga (including) 12.2sga (including)
Ios Cisco 12.2sm (including) 12.2sm (including)
Ios Cisco 12.2so (including) 12.2so (including)
Ios Cisco 12.2sr (including) 12.2sr (including)
Ios Cisco 12.2sra (including) 12.2sra (including)
Ios Cisco 12.2srb (including) 12.2srb (including)
Ios Cisco 12.2src (including) 12.2src (including)
Ios Cisco 12.2su (including) 12.2su (including)
Ios Cisco 12.2sv (including) 12.2sv (including)
Ios Cisco 12.2sva (including) 12.2sva (including)
Ios Cisco 12.2svc (including) 12.2svc (including)
Ios Cisco 12.2svd (including) 12.2svd (including)
Ios Cisco 12.2sve (including) 12.2sve (including)
Ios Cisco 12.2sw (including) 12.2sw (including)
Ios Cisco 12.2sx (including) 12.2sx (including)
Ios Cisco 12.2sxa (including) 12.2sxa (including)
Ios Cisco 12.2sxb (including) 12.2sxb (including)
Ios Cisco 12.2sxd (including) 12.2sxd (including)
Ios Cisco 12.2sxe (including) 12.2sxe (including)
Ios Cisco 12.2sxf (including) 12.2sxf (including)
Ios Cisco 12.2sy (including) 12.2sy (including)
Ios Cisco 12.2sz (including) 12.2sz (including)
Ios Cisco 12.2t (including) 12.2t (including)
Ios Cisco 12.2tpc (including) 12.2tpc (including)
Ios Cisco 12.2xa (including) 12.2xa (including)
Ios Cisco 12.2xb (including) 12.2xb (including)
Ios Cisco 12.2xc (including) 12.2xc (including)
Ios Cisco 12.2xd (including) 12.2xd (including)
Ios Cisco 12.2xe (including) 12.2xe (including)
Ios Cisco 12.2xf (including) 12.2xf (including)
Ios Cisco 12.2xg (including) 12.2xg (including)
Ios Cisco 12.2xh (including) 12.2xh (including)
Ios Cisco 12.2xi (including) 12.2xi (including)
Ios Cisco 12.2xj (including) 12.2xj (including)
Ios Cisco 12.2xk (including) 12.2xk (including)
Ios Cisco 12.2xl (including) 12.2xl (including)
Ios Cisco 12.2xm (including) 12.2xm (including)
Ios Cisco 12.2xn (including) 12.2xn (including)
Ios Cisco 12.2xo (including) 12.2xo (including)
Ios Cisco 12.2xq (including) 12.2xq (including)
Ios Cisco 12.2xr (including) 12.2xr (including)
Ios Cisco 12.2xs (including) 12.2xs (including)
Ios Cisco 12.2xt (including) 12.2xt (including)
Ios Cisco 12.2xu (including) 12.2xu (including)
Ios Cisco 12.2xv (including) 12.2xv (including)
Ios Cisco 12.2xw (including) 12.2xw (including)
Ios Cisco 12.2ya (including) 12.2ya (including)
Ios Cisco 12.2yb (including) 12.2yb (including)
Ios Cisco 12.2yc (including) 12.2yc (including)
Ios Cisco 12.2yd (including) 12.2yd (including)
Ios Cisco 12.2ye (including) 12.2ye (including)
Ios Cisco 12.2yf (including) 12.2yf (including)
Ios Cisco 12.2yg (including) 12.2yg (including)
Ios Cisco 12.2yh (including) 12.2yh (including)
Ios Cisco 12.2yj (including) 12.2yj (including)
Ios Cisco 12.2yk (including) 12.2yk (including)
Ios Cisco 12.2yl (including) 12.2yl (including)
Ios Cisco 12.2ym (including) 12.2ym (including)
Ios Cisco 12.2yn (including) 12.2yn (including)
Ios Cisco 12.2yo (including) 12.2yo (including)
Ios Cisco 12.2yp (including) 12.2yp (including)
Ios Cisco 12.2yq (including) 12.2yq (including)
Ios Cisco 12.2yr (including) 12.2yr (including)
Ios Cisco 12.2ys (including) 12.2ys (including)
Ios Cisco 12.2yt (including) 12.2yt (including)
Ios Cisco 12.2yu (including) 12.2yu (including)
Ios Cisco 12.2yv (including) 12.2yv (including)
Ios Cisco 12.2yw (including) 12.2yw (including)
Ios Cisco 12.2yx (including) 12.2yx (including)
Ios Cisco 12.2yy (including) 12.2yy (including)
Ios Cisco 12.2yz (including) 12.2yz (including)
Ios Cisco 12.2za (including) 12.2za (including)
Ios Cisco 12.2zb (including) 12.2zb (including)
Ios Cisco 12.2zc (including) 12.2zc (including)
Ios Cisco 12.2zd (including) 12.2zd (including)
Ios Cisco 12.2ze (including) 12.2ze (including)
Ios Cisco 12.2zf (including) 12.2zf (including)
Ios Cisco 12.2zg (including) 12.2zg (including)
Ios Cisco 12.2zh (including) 12.2zh (including)
Ios Cisco 12.2zj (including) 12.2zj (including)
Ios Cisco 12.2zl (including) 12.2zl (including)
Ios Cisco 12.2zp (including) 12.2zp (including)
Ios Cisco 12.2zu (including) 12.2zu (including)
Ios Cisco 12.2zx (including) 12.2zx (including)
Ios Cisco 12.2zy (including) 12.2zy (including)
Ios Cisco 12.2zya (including) 12.2zya (including)
Ios Cisco 12.4 (including) 12.4 (including)
Ios Cisco 12.4(1) (including) 12.4(1) (including)
Ios Cisco 12.4(1b) (including) 12.4(1b) (including)
Ios Cisco 12.4(1c) (including) 12.4(1c) (including)
Ios Cisco 12.4(2)mr (including) 12.4(2)mr (including)
Ios Cisco 12.4(2)mr1 (including) 12.4(2)mr1 (including)
Ios Cisco 12.4(2)t (including) 12.4(2)t (including)
Ios Cisco 12.4(2)t1 (including) 12.4(2)t1 (including)
Ios Cisco 12.4(2)t2 (including) 12.4(2)t2 (including)
Ios Cisco 12.4(2)t3 (including) 12.4(2)t3 (including)
Ios Cisco 12.4(2)t4 (including) 12.4(2)t4 (including)
Ios Cisco 12.4(2)xa (including) 12.4(2)xa (including)
Ios Cisco 12.4(2)xb (including) 12.4(2)xb (including)
Ios Cisco 12.4(2)xb2 (including) 12.4(2)xb2 (including)
Ios Cisco 12.4(3) (including) 12.4(3) (including)
Ios Cisco 12.4(3)t2 (including) 12.4(3)t2 (including)
Ios Cisco 12.4(3a) (including) 12.4(3a) (including)
Ios Cisco 12.4(3b) (including) 12.4(3b) (including)
Ios Cisco 12.4(3d) (including) 12.4(3d) (including)
Ios Cisco 12.4(4)mr (including) 12.4(4)mr (including)
Ios Cisco 12.4(4)t (including) 12.4(4)t (including)
Ios Cisco 12.4(4)t2 (including) 12.4(4)t2 (including)
Ios Cisco 12.4(5) (including) 12.4(5) (including)
Ios Cisco 12.4(5b) (including) 12.4(5b) (including)
Ios Cisco 12.4(6)t (including) 12.4(6)t (including)
Ios Cisco 12.4(6)t1 (including) 12.4(6)t1 (including)
Ios Cisco 12.4(7) (including) 12.4(7) (including)
Ios Cisco 12.4(7a) (including) 12.4(7a) (including)
Ios Cisco 12.4(8) (including) 12.4(8) (including)
Ios Cisco 12.4(9)t (including) 12.4(9)t (including)
Ios Cisco 12.4(23) (including) 12.4(23) (including)
Ios Cisco 12.4ja (including) 12.4ja (including)
Ios Cisco 12.4jda (including) 12.4jda (including)
Ios Cisco 12.4jk (including) 12.4jk (including)
Ios Cisco 12.4jl (including) 12.4jl (including)
Ios Cisco 12.4jma (including) 12.4jma (including)
Ios Cisco 12.4jmb (including) 12.4jmb (including)
Ios Cisco 12.4jx (including) 12.4jx (including)
Ios Cisco 12.4md (including) 12.4md (including)
Ios Cisco 12.4mr (including) 12.4mr (including)
Ios Cisco 12.4s (including) 12.4s (including)
Ios Cisco 12.4sw (including) 12.4sw (including)
Ios Cisco 12.4t (including) 12.4t (including)
Ios Cisco 12.4xa (including) 12.4xa (including)
Ios Cisco 12.4xb (including) 12.4xb (including)
Ios Cisco 12.4xc (including) 12.4xc (including)
Ios Cisco 12.4xd (including) 12.4xd (including)
Ios Cisco 12.4xe (including) 12.4xe (including)
Ios Cisco 12.4xf (including) 12.4xf (including)
Ios Cisco 12.4xg (including) 12.4xg (including)
Ios Cisco 12.4xj (including) 12.4xj (including)
Ios Cisco 12.4xk (including) 12.4xk (including)
Ios Cisco 12.4xl (including) 12.4xl (including)
Ios Cisco 12.4xm (including) 12.4xm (including)
Ios Cisco 12.4xn (including) 12.4xn (including)
Ios Cisco 12.4xp (including) 12.4xp (including)
Ios Cisco 12.4xt (including) 12.4xt (including)
Ios Cisco 12.4xv (including) 12.4xv (including)
Ios Cisco 12.4xw (including) 12.4xw (including)
Ios Cisco 12.4xy (including) 12.4xy (including)
Ios_xr Cisco 12.4 (including) 12.4 (including)

References