Page 2 of 9 results (0.003 seconds)

CVSS: 7.5EPSS: 3%CPEs: 1EXPL: 0

Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges. • http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html https://exchange.xforce.ibmcloud.com/vulnerabilities/44544 •

CVSS: 5.0EPSS: 0%CPEs: 15EXPL: 2

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets. • https://www.exploit-db.com/exploits/21092 http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml http://www.securityfocus.com/bid/3236 https://exchange.xforce.ibmcloud.com/vulnerabilities/7025 https://exchange.xforce.ibmcloud.com/vulnerabilities/7026 •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. • http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml https://exchange.xforce.ibmcloud.com/vulnerabilities/7027 •

CVSS: 2.1EPSS: 0%CPEs: 2EXPL: 2

Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information. • http://archives.neohapsis.com/archives/bugtraq/2001-04/0380.html http://www.osvdb.org/1796 http://www.securityfocus.com/bid/2635 https://exchange.xforce.ibmcloud.com/vulnerabilities/6453 •