Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability

BID:16291

Info

Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability

Bugtraq ID: 16291
Class: Input Validation Error
CVE: CVE-2005-3921
Remote: Yes
Local: No
Published: Jan 17 2006 12:00AM
Updated: Mar 19 2015 09:43AM
Credit: Discovered by Digitalmunitions.com.
Vulnerable: Cisco IOS 11.3.11 b
Cisco IOS 11.3.1 T
Cisco IOS 11.3.1 ED
Cisco IOS 11.3.1
Cisco IOS 11.2.10 BC
Cisco IOS 11.2.10
Cisco IOS 11.2.9 XA
Cisco IOS 11.2.9 P
Cisco IOS 11.2.8 SA5
Cisco IOS 11.2.8 SA3
Cisco IOS 11.2.8 SA1
Cisco IOS 11.2.8 P
Cisco IOS 11.2.8
Cisco IOS 11.2.4 F1
Cisco IOS 11.2.4 F
Cisco IOS 11.2.4
Cisco IOS 11.1.17 CT
Cisco IOS 11.1.17 CC
Cisco IOS 11.1.16 IA
Cisco IOS 11.1.16 AA
Cisco IOS 11.1.16
Cisco IOS 11.1.15 IA
Cisco IOS 11.1.15 CA
Cisco IOS 11.1.15 AA
Cisco IOS 11.1.15
Cisco IOS 11.1.13 IA
Cisco IOS 11.1.13 CA
Cisco IOS 11.1.13 AA
Cisco IOS 11.1.13
Cisco IOS 11.1.9 IA
Cisco IOS 11.1.7 CA
Cisco IOS 11.1.7 AA
Cisco IOS 11.1.7
Cisco IOS 11.0.20 .3
Cisco IOS 11.0.17 BT
Cisco IOS 11.0.17
Cisco IOS 11.0.12 (a)BT
Cisco IOS 11.0.12
Cisco IOS 11.3XA
Cisco IOS 11.3WA4
Cisco IOS 11.3T
Cisco IOS 11.3NA
Cisco IOS 11.3MA
Cisco IOS 11.3HA
Cisco IOS 11.3DB
Cisco IOS 11.3DA
Cisco IOS 11.3AA
Cisco IOS 11.3(8)DB2
Cisco IOS 11.3(7)DB1
Cisco IOS 11.3(2)XA
Cisco IOS 11.3(11d)
Cisco IOS 11.3(11c)
Cisco IOS 11.3(11b)T2
Cisco IOS 11.3(11b)
Cisco IOS 11.3
Cisco IOS 11.2XA
Cisco IOS 11.2WA4
Cisco IOS 11.2WA3
Cisco IOS 11.2SA
Cisco IOS 11.2P
Cisco IOS 11.2GS
Cisco IOS 11.2F
Cisco IOS 11.2BC
Cisco IOS 11.2(9)XA
Cisco IOS 11.2(8.9)SA6
Cisco IOS 11.2(8.11)SA6
Cisco IOS 11.2(4)XAf
Cisco IOS 11.2(4)XA
Cisco IOS 11.2(4)
Cisco IOS 11.2(26e)
Cisco IOS 11.2(26b)
Cisco IOS 11.2(26a)
Cisco IOS 11.2(26)P5
Cisco IOS 11.2(26)P2
Cisco IOS 11.2(23a)BC1
Cisco IOS 11.2(19a)GS6
Cisco IOS 11.2(19)GS0.2
Cisco IOS 11.2(17)
Cisco IOS 11.2(15b)
Cisco IOS 11.2(11b)T2
Cisco IOS 11.2
Cisco IOS 11.1IA
Cisco IOS 11.1CT
Cisco IOS 11.1CC
Cisco IOS 11.1CA
Cisco IOS 11.1AA
Cisco IOS 11.1(36)CC4
Cisco IOS 11.1(36)CC2
Cisco IOS 11.1(36)CA4
Cisco IOS 11.1(36)CA2
Cisco IOS 11.1(28a)IA
Cisco IOS 11.1(28a)CT
Cisco IOS 11.1(24c)
Cisco IOS 11.1(24b)
Cisco IOS 11.1(24a)
Cisco IOS 11.1(20)AA4
Cisco IOS 11.1
Cisco IOS 11.0x
Cisco IOS 11.0(22b)
Cisco IOS 11.0(22a)
Cisco IOS 11.0(18)
Cisco IOS 11.0
Not Vulnerable:

Discussion

Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability

Cisco IOS HTTP service is reportedly prone to an HTML injection vulnerability that affects the Cisco Discovery Protocol (CDP) status page. An attacker can submit malicious HTML and script code through CDP packets to be run in the context of a logged-in administrator. The attacker can also run arbitrary commands on a vulnerable device.

Successful exploits may allow the attacker to manipulate routing information, create accounts, and access all other functionality available to administrators.

IOS 11.2(8.11)SA6 is vulnerable; other versions of IOS 11 are likely affected as well. This issue does not affect IOS 12.

Exploit / POC

Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability

An exploit is not required.

Solution / Fix

Cisco IOS HTTP Service CDP Status Page HTML Injection Vulnerability

Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report