Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
BID:16291
Info
Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
| Bugtraq ID: | 16291 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3921 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2006 12:00AM |
| Updated: | Mar 19 2015 09:43AM |
| Credit: | Discovered by Digitalmunitions.com. |
| Vulnerable: |
Cisco IOS 11.3.11 b Cisco IOS 11.3.1 T Cisco IOS 11.3.1 ED Cisco IOS 11.3.1 Cisco IOS 11.2.10 BC Cisco IOS 11.2.10 Cisco IOS 11.2.9 XA Cisco IOS 11.2.9 P Cisco IOS 11.2.8 SA5 Cisco IOS 11.2.8 SA3 Cisco IOS 11.2.8 SA1 Cisco IOS 11.2.8 P Cisco IOS 11.2.8 Cisco IOS 11.2.4 F1 Cisco IOS 11.2.4 F Cisco IOS 11.2.4 Cisco IOS 11.1.17 CT Cisco IOS 11.1.17 CC Cisco IOS 11.1.16 IA Cisco IOS 11.1.16 AA Cisco IOS 11.1.16 Cisco IOS 11.1.15 IA Cisco IOS 11.1.15 CA Cisco IOS 11.1.15 AA Cisco IOS 11.1.15 Cisco IOS 11.1.13 IA Cisco IOS 11.1.13 CA Cisco IOS 11.1.13 AA Cisco IOS 11.1.13 Cisco IOS 11.1.9 IA Cisco IOS 11.1.7 CA Cisco IOS 11.1.7 AA Cisco IOS 11.1.7 Cisco IOS 11.0.20 .3 Cisco IOS 11.0.17 BT Cisco IOS 11.0.17 Cisco IOS 11.0.12 (a)BT Cisco IOS 11.0.12 Cisco IOS 11.3XA Cisco IOS 11.3WA4 Cisco IOS 11.3T Cisco IOS 11.3NA Cisco IOS 11.3MA Cisco IOS 11.3HA Cisco IOS 11.3DB Cisco IOS 11.3DA Cisco IOS 11.3AA Cisco IOS 11.3(8)DB2 Cisco IOS 11.3(7)DB1 Cisco IOS 11.3(2)XA Cisco IOS 11.3(11d) Cisco IOS 11.3(11c) Cisco IOS 11.3(11b)T2 Cisco IOS 11.3(11b) Cisco IOS 11.3 Cisco IOS 11.2XA Cisco IOS 11.2WA4 Cisco IOS 11.2WA3 Cisco IOS 11.2SA Cisco IOS 11.2P Cisco IOS 11.2GS Cisco IOS 11.2F Cisco IOS 11.2BC Cisco IOS 11.2(9)XA Cisco IOS 11.2(8.9)SA6 Cisco IOS 11.2(8.11)SA6 Cisco IOS 11.2(4)XAf Cisco IOS 11.2(4)XA Cisco IOS 11.2(4) Cisco IOS 11.2(26e) Cisco IOS 11.2(26b) Cisco IOS 11.2(26a) Cisco IOS 11.2(26)P5 Cisco IOS 11.2(26)P2 Cisco IOS 11.2(23a)BC1 Cisco IOS 11.2(19a)GS6 Cisco IOS 11.2(19)GS0.2 Cisco IOS 11.2(17) Cisco IOS 11.2(15b) Cisco IOS 11.2(11b)T2 Cisco IOS 11.2 Cisco IOS 11.1IA Cisco IOS 11.1CT Cisco IOS 11.1CC Cisco IOS 11.1CA Cisco IOS 11.1AA Cisco IOS 11.1(36)CC4 Cisco IOS 11.1(36)CC2 Cisco IOS 11.1(36)CA4 Cisco IOS 11.1(36)CA2 Cisco IOS 11.1(28a)IA Cisco IOS 11.1(28a)CT Cisco IOS 11.1(24c) Cisco IOS 11.1(24b) Cisco IOS 11.1(24a) Cisco IOS 11.1(20)AA4 Cisco IOS 11.1 Cisco IOS 11.0x Cisco IOS 11.0(22b) Cisco IOS 11.0(22a) Cisco IOS 11.0(18) Cisco IOS 11.0 |
| Not Vulnerable: | |
Discussion
Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
Cisco IOS HTTP service is reportedly prone to an HTML injection vulnerability that affects the Cisco Discovery Protocol (CDP) status page. An attacker can submit malicious HTML and script code through CDP packets to be run in the context of a logged-in administrator. The attacker can also run arbitrary commands on a vulnerable device.
Successful exploits may allow the attacker to manipulate routing information, create accounts, and access all other functionality available to administrators.
IOS 11.2(8.11)SA6 is vulnerable; other versions of IOS 11 are likely affected as well. This issue does not affect IOS 12.
Cisco IOS HTTP service is reportedly prone to an HTML injection vulnerability that affects the Cisco Discovery Protocol (CDP) status page. An attacker can submit malicious HTML and script code through CDP packets to be run in the context of a logged-in administrator. The attacker can also run arbitrary commands on a vulnerable device.
Successful exploits may allow the attacker to manipulate routing information, create accounts, and access all other functionality available to administrators.
IOS 11.2(8.11)SA6 is vulnerable; other versions of IOS 11 are likely affected as well. This issue does not affect IOS 12.
Exploit / POC
Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability
References:
References: