Vulnerability Description
Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cbos | <= 2.4.2ap |
References
- http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7027
- http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7027
FAQ
What is CVE-2001-1065?
CVE-2001-1065 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the ro...
How severe is CVE-2001-1065?
CVE-2001-1065 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1065?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Cbos.