CVE-2009-0637

Cisco IOS <12.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1021899
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49423
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34438
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34247
Not Applicable vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0851

Scores

EPSS 0.0332
EPSS Percentile 87.3%

Details

CWE
CWE-264
Status published
Products (50)
cisco/ios 12.2
cisco/ios 12.2b
cisco/ios 12.2bc
cisco/ios 12.2bw
cisco/ios 12.2bx
cisco/ios 12.2by
cisco/ios 12.2bz
cisco/ios 12.2ca
cisco/ios 12.2cx
cisco/ios 12.2cy
... and 40 more
Published Mar 27, 2009
Tracked Since Feb 18, 2026