CVE-2001-0537 describes a critical authentication bypass vulnerability in the HTTP server of Cisco IOS versions 11.3 through 12.2. Attackers can exploit this flaw by manipulating the URL to specify a high access level, thereby bypassing local authorization and executing arbitrary commands. This vulnerability carries a CVSS score of 9.3 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, extensive exploit intelligence exists, including Metasploit modules, Nuclei templates, and multiple ExploitDB entries, indicating readily available exploitation tools.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.3:*:*:*:*:*:*:* | ||
11.3aaCPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.3aa:*:*:*:*:*:*:* | ||
11.3daCPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.3da:*:*:*:*:*:*:* | ||
11.3dbCPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.3db:*:*:*:*:*:*:* | ||
11.3haCPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.3ha:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.