CVE-2007-2586 describes a critical authorization bypass vulnerability in the FTP Server component of Cisco IOS versions 11.3 through 12.4. This flaw allows unauthenticated remote attackers to execute arbitrary code, read sensitive configuration files (like startup-config), and potentially gain full control of affected devices. The vulnerability is triggered by a crafted MKD command, which can lead to a buffer overflow when interacting with a VTY device. Rated with a CVSS score of 9.3, this vulnerability is highly severe, requiring no authentication (Au:N) and having a medium attack complexity (AC:M) but complete confidentiality, integrity, and availability impact (C:C/I:C/A:C). Its high EPSS score and FAUCET Risk Score of 98/100 further underscore its potential danger. While not listed on the KEV catalog or Hot List, an exploit (EDB-6155) for Cisco IOS 12.3(18) exists on ExploitDB, indicating public knowledge of exploitation methods. Despite this, there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0\(1\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)t:*:*:*:*:*:*:* | ||
12.0\(1\)t1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)t1:*:*:*:*:*:*:* | ||
12.0\(1\)xeCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(1\)xe:*:*:*:*:*:*:* | ||
12.0\(2\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(2\)s:*:*:*:*:*:*:* | ||
12.0\(2\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.0\(2\)t:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.