CVE-2007-2586: Critical severity Cisco IOS vulnerability
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2586?
CVE-2007-2586 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2007-2586?
To fix CVE-2007-2586, update your Cisco IOS to a version that has patched this vulnerability.
Which versions of Cisco IOS are affected by CVE-2007-2586?
CVE-2007-2586 affects Cisco IOS versions from 11.3 through 12.4.
Can CVE-2007-2586 lead to unauthorized access?
Yes, CVE-2007-2586 potentially allows attackers to execute arbitrary commands, which can lead to unauthorized access.
Is there a known exploit for CVE-2007-2586?
Yes, crafted MKD commands have been demonstrated to exploit CVE-2007-2586, allowing remote code execution.