Vulnerability Description
The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Network Analysis Module | All versions |
| Cisco | Catalyst 6000 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 6000 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 6000 Ws-X6380-Nam | 3.1\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 6500 Ws-X6380-Nam | 3.1\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-1 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-Svc-Nam-2 | 2.2\(1a\) |
| Cisco | Catalyst 7600 Ws-X6380-Nam | 3.1\(1a\) |
Related Weaknesses (CWE)
References
- http://osvdb.org/33066
- http://secunia.com/advisories/24344Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/472412US Government Resource
- http://www.securityfocus.com/bid/22751
- http://www.securitytracker.com/id?1017710
- http://www.vupen.com/english/advisories/2007/0783
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32750
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://osvdb.org/33066
- http://secunia.com/advisories/24344Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/472412US Government Resource
- http://www.securityfocus.com/bid/22751
- http://www.securitytracker.com/id?1017710
FAQ
What is CVE-2007-1257?
CVE-2007-1257 is a vulnerability with a CVSS score of 10.0 (HIGH). The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP ad...
How severe is CVE-2007-1257?
CVE-2007-1257 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1257?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Network Analysis Module, Cisco Catalyst 6000 Ws-Svc-Nam-1, Cisco Catalyst 6000 Ws-Svc-Nam-2, Cisco Catalyst 6000 Ws-X6380-Nam, Cisco Catalyst 6500 Ws-Svc-Nam-1.