Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco IOS Secure Copy Security Bypass Vulnerability

Cisco IOS secure copy server is prone to a remote security-bypass vulnerability because the application fails to properly validate user privileges during a secure copy.

Exploiting this issue allows remote attackers to retrieve, write, or overwrite arbitrary files on the device's filesystem, including configuration and password files. Successful exploits will result in a complete compromise of affected devices.

This issue affects Cisco 12.2-based IOS with the secure copy server feature enabled. This feature is not enabled by default.

This issue is being tracked by Cisco Bug ID CSCsc19259.







 

Privacy Statement
Copyright 2009, SecurityFocus