Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-0637

EPSS 1.28% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-0637

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco IOS 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOS是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS软件中SCP实现的服务器端存在权限许可和访问控制问题漏洞,可能允许附加了CLI视图的认证用户从配置为SCP服务器的Cisco IOS设备传输文件,无论CLI视图配置授权给哪些用户上述权限。这个漏洞允许有效用户在设备的系统文件上检索或写入任意文件(包括设备保存的配置和Cisco IOS镜像文件),即使附加给用户的CLI视图不允许这些操作。配置文件中可能包含有口令或其他敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-0637

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-0637

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-03-27 · 15 CVEs total

CVE-2009-0590OpenSSL 缓冲区错误漏洞
CVE-2009-0591OpenSSL 授权问题漏洞
CVE-2009-0626Cisco IOS WebVPN/SSLVPN HTTPS报文 远程拒绝服务漏洞
CVE-2009-0628Cisco IOS WebVPN/SSLVPN 内存泄露漏洞
CVE-2009-0629Cisco IOS 安全漏洞
CVE-2009-0630Cisco IOS多个功能IP套接字拒绝服务漏洞
CVE-2009-0633Cisco IOS移动IP/移动IPv6功能多个远程拒绝服务漏洞
CVE-2009-0634Cisco IOS移动IP/移动IPv6功能 HA功能多个远程拒绝服务漏洞
CVE-2009-0635Cisco IOS cTCP协议远程拒绝服务漏洞
CVE-2009-0636Cisco IOS会话初始协议拒绝服务漏洞
CVE-2009-0789OpenSSL 数字错误漏洞
CVE-2009-0845MIT Kerberos NegTokenInit令牌处理远程拒绝服务漏洞
CVE-2009-0631Cisco IOS多个功能UDP报文拒绝服务漏洞
CVE-2009-1169Mozilla Firefox XSL解析root XML标签内存破坏漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-0637

No comments yet


Leave a comment