Vulnerability CVE-2000-0345


Published: 2000-05-03   Modified: 2012-02-12

Description:
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.

Vendor: Cisco
Product: IOS 
Version:
9.14
12.0t
12.0s
12.0db
12.0(9)s
12.0(8)
12.0(7)t
12.0(6)
12.0(5)t1
12.0(5)
12.0(4)t
12.0(4)s
12.0(4)
12.0(3)t2
12.0(2)xg
12.0(2)xf
12.0(2)xd
12.0(2)xc
12.0(2)
12.0(1)xe
12.0(1)xb
12.0(1)xa3
12.0(1)w
12.0
11.2p
11.2(9)xa
11.2(9)p
11.2(8)sa5
11.2(8)sa3
11.2(8)sa1
11.2(8)p
11.2(8)
11.2(4)f1
11.2(17)
11.2(10)bc
11.2(10)
11.2
11.1(17)ct
11.1(17)cc
11.1(16)ia
11.1(16)aa
11.1(16)
11.1(15)ca
11.1(13)ia
11.1(13)ca
11.1(13)aa
11.1(13)
11.1
Product: Router 7500 
Product: Router 2500 
Product: Router 3600 
Product: Router 7200 
Product: Router 2600 
Product: Router 4000 

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://www.securityfocus.com/bid/1161
http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000502222246.28423.qmail@securityfocus.com

Related CVE
CVE-2019-1700
A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent at...
CVE-2019-1685
A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface o...
CVE-2019-1681
A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retrieve arbitrary files from the targeted device, possibly resulting in information disclosure. The vulne...
CVE-2019-1667
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attacker could e...
CVE-2019-1666
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploi...
CVE-2019-1665
A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected syste...
CVE-2019-1664
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could expl...
CVE-2019-1662
A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient auth...

Copyright 2019, cxsecurity.com

 

Back to Top