CVE-2007-5549: Infoleak
Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods", aka CSCsk16129. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5549?
CVE-2007-5549 is considered a serious vulnerability due to its potential to allow local users to bypass command restrictions.
How do I fix CVE-2007-5549?
To mitigate CVE-2007-5549, you should apply the latest security patches provided by Cisco for your version of IOS.
Who is affected by CVE-2007-5549?
CVE-2007-5549 impacts users of Cisco IOS who have local access and permissions for executing commands.
What kind of attacks can occur because of CVE-2007-5549?
CVE-2007-5549 can lead to sensitive information exposure due to unauthorized command execution.
Is CVE-2007-5549 a remote vulnerability?
No, CVE-2007-5549 is a local vulnerability that requires local access to exploit.