CVE-2000-0345: Low severity Cisco IOS vulnerability

Published May 3, 2000
·
Updated

The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.

Affected Software

54 affected components
Cisco IOS=9.14
Cisco IOS=11.1
Cisco IOS=11.1\(13\)
Cisco IOS=11.1\(13\)aa
Cisco IOS=11.1\(13\)ca
Cisco IOS=11.1\(13\)ia
Cisco IOS=11.1\(15\)ca
Cisco IOS=11.1\(16\)
Cisco IOS=11.1\(16\)aa
Cisco IOS=11.1\(16\)ia
Cisco IOS=11.1\(17\)cc
Cisco IOS=11.1\(17\)ct
Cisco IOS=11.2
Cisco IOS=11.2\(4\)f1
Cisco IOS=11.2\(8\)
Cisco IOS=11.2\(8\)p
Cisco IOS=11.2\(8\)sa1
Cisco IOS=11.2\(8\)sa3
Cisco IOS=11.2\(8\)sa5
Cisco IOS=11.2\(9\)p
Cisco IOS=11.2\(9\)xa
Cisco IOS=11.2\(10\)
Cisco IOS=11.2\(10\)bc
Cisco IOS=11.2\(17\)
Cisco IOS=11.2p
Cisco IOS=12.0
Cisco IOS=12.0\(1\)w
Cisco IOS=12.0\(1\)xa3
Cisco IOS=12.0\(1\)xb
Cisco IOS=12.0\(1\)xe
Cisco IOS=12.0\(2\)
Cisco IOS=12.0\(2\)xc
Cisco IOS=12.0\(2\)xd
Cisco IOS=12.0\(2\)xf
Cisco IOS=12.0\(2\)xg
Cisco IOS=12.0\(3\)t2
Cisco IOS=12.0\(4\)
Cisco IOS=12.0\(4\)s
Cisco IOS=12.0\(4\)t
Cisco IOS=12.0\(5\)
Cisco IOS=12.0\(5\)t1
Cisco IOS=12.0\(6\)
Cisco IOS=12.0\(7\)t
Cisco IOS=12.0\(8\)
Cisco IOS=12.0\(9\)s
Cisco IOS=12.0db
Cisco IOS=12.0s
Cisco IOS=12.0t
Cisco Router 2500
Cisco Router 2600
Cisco Router 3600
Cisco Router 4000
Cisco Router 7200
Cisco Router 7500

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the on-line help system options on affected routers to prevent non-privileged users from using help features to access sensitive information.

    Cisco router (on-line help system) on-line help system options = disabled
  2. Configuration

    Configure command privilege levels so that 'show' commands require enabled/privileged access, preventing non-privileged users from obtaining sensitive information via the show command.

    Cisco router (command privilege configuration) privilege level for 'show' commands = require 'enabled' (privileged)

Event History

May 3, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
May 18, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2000-0345?

The severity of CVE-2000-0345 is considered to be moderate, as it allows non-privileged users to access sensitive information.

2

How do I fix CVE-2000-0345?

To fix CVE-2000-0345, it is recommended to upgrade to a patched version of Cisco IOS that resolves this vulnerability.

3

What versions of Cisco IOS are affected by CVE-2000-0345?

CVE-2000-0345 affects multiple versions of Cisco IOS, including 11.1 and 12.0 variants.

4

Can CVE-2000-0345 be exploited remotely?

Yes, CVE-2000-0345 can be exploited remotely if the router's configuration allows non-privileged access.

5

What impacts does CVE-2000-0345 have on network security?

CVE-2000-0345 could lead to unauthorized disclosure of sensitive information, potentially compromising network security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203