Vulnerability CVE-2000-0345


Published: 2000-05-03   Modified: 2012-02-12

Description:
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.

Vendor: Cisco
Product: IOS 
Version:
9.14
12.0t
12.0s
12.0db
12.0(9)s
12.0(8)
12.0(7)t
12.0(6)
12.0(5)t1
12.0(5)
12.0(4)t
12.0(4)s
12.0(4)
12.0(3)t2
12.0(2)xg
12.0(2)xf
12.0(2)xd
12.0(2)xc
12.0(2)
12.0(1)xe
12.0(1)xb
12.0(1)xa3
12.0(1)w
12.0
11.2p
11.2(9)xa
11.2(9)p
11.2(8)sa5
11.2(8)sa3
11.2(8)sa1
11.2(8)p
11.2(8)
11.2(4)f1
11.2(17)
11.2(10)bc
11.2(10)
11.2
11.1(17)ct
11.1(17)cc
11.1(16)ia
11.1(16)aa
11.1(16)
11.1(15)ca
11.1(13)ia
11.1(13)ca
11.1(13)aa
11.1(13)
11.1
Product: Router 7500 
Product: Router 2500 
Product: Router 3600 
Product: Router 7200 
Product: Router 2600 
Product: Router 4000 

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://www.securityfocus.com/bid/1161
http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000502222246.28423.qmail@securityfocus.com

Related CVE
CVE-2019-1780
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevate...
CVE-2019-1860
A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center....
CVE-2019-1853
A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software...
CVE-2019-1849
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition...
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent atta...
CVE-2019-1833
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due ...
CVE-2019-1832
A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies. The vulnerability is due to improper validation of ICMP packets. An...
CVE-2019-1818
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that sho...

Copyright 2019, cxsecurity.com

 

Back to Top