CVE-2001-1434 describes a vulnerability in specific versions of Cisco IOS (12.0(5)XU through 12.1(2)). It allows remote attackers to access sensitive system administration and network topology information. This occurs when an "snmp-server host" command is used without a pre-existing community string, causing a readable "community" string to be created. Rated with a CVSS score of 5.0 (Medium), this vulnerability has a low attack complexity and requires no authentication, allowing for remote information disclosure (C:P). The primary impact is the unauthorized reading of configuration and topology data, with no impact on integrity or availability. There is no evidence of active exploitation, and no public exploit code exists in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received no community discussion or media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0:*:*:*:*:*:*:* | ||
12.0\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\):*:*:*:*:*:*:* | ||
12.0\(1\)wCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)w:*:*:*:*:*:*:* | ||
12.0\(1\)xa3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)xa3:*:*:*:*:*:*:* | ||
12.0\(1\)xbCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)xb:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.