Cisco IOS Cross-Site Request Forgery Vulnerability
中危 CVSS 4.3 CISA KEV 在册
摘要
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- Cisco:IOS
- :
Lint 边界警告 (4)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://www.securityfocus.com/bid/31218 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://exchange.xforce.ibmcloud.com/vulnerabilities/45226 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
数据来源
- CISA KEV DATABASE
- NVD DATABASE
原始链接
- https://nvd.nist.gov/vuln/detail/CVE-2008-4128 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html Broken Link
- http://www.securityfocus.com/bid/31218 Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226 Third Party Advisory
- https://www.exploit-db.com/exploits/6476 Exploit
- https://www.exploit-db.com/exploits/6477 Exploit
- https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128 US Government Resource
- https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html Product
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
时间线
- kev_added CISA KEV
- nvd_ingest NVD
- kev_ingest CISA KEV