CVE-2000-0345: Low severity Cisco IOS vulnerability
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the on-line help system options on affected routers to prevent non-privileged users from using help features to access sensitive information.
Cisco router (on-line help system) on-line help system options = disabled - Configuration
Configure command privilege levels so that 'show' commands require enabled/privileged access, preventing non-privileged users from obtaining sensitive information via the show command.
Cisco router (command privilege configuration) privilege level for 'show' commands = require 'enabled' (privileged)
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0345?
The severity of CVE-2000-0345 is considered to be moderate, as it allows non-privileged users to access sensitive information.
How do I fix CVE-2000-0345?
To fix CVE-2000-0345, it is recommended to upgrade to a patched version of Cisco IOS that resolves this vulnerability.
What versions of Cisco IOS are affected by CVE-2000-0345?
CVE-2000-0345 affects multiple versions of Cisco IOS, including 11.1 and 12.0 variants.
Can CVE-2000-0345 be exploited remotely?
Yes, CVE-2000-0345 can be exploited remotely if the router's configuration allows non-privileged access.
What impacts does CVE-2000-0345 have on network security?
CVE-2000-0345 could lead to unauthorized disclosure of sensitive information, potentially compromising network security.