CVE-2001-1065

Cisco CBOS 2.0.1-2.4.2ap - Unauthenticated Web Configuration Utility Exposure via Port 80 Binding

Title source: llm
STIX 2.1

Description

Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7027
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml

Scores

EPSS 0.0108
EPSS Percentile 61.7%

Details

Status published
Products (2)
cisco/cbos 2.0.1
cisco/cbos < 2.4.2ap
Published Aug 31, 2001
Tracked Since Feb 18, 2026