Protection against Cisco IOS HTTP Server Code Injection Vulnerability
| Attack ID: | CPAI-2005-159 |
| Publish Date: | |
| Category: | Command Injection |
| Vulnerable Systems: | All Cisco products that run Cisco Software versions 11.0 through 12.4 with the HTTP server enabled |
| Source: | Cisco Security Advisory ID: 68322 |
| Description: | A vulnerability exists in Cisco's IOS HTTP server. The Cisco HTTP Server is used to manage cisco routers via Web browser. An attacker can submit malicious HTML and script code through several scripts and potentially execute malicious commands against the affected device. Devices with the HTTP service disabled are not affected. |
| Severity: | |
| Details: | Several functions do not properly filter HTML code from user-supplied inputs before displaying the input. An attacker can inject arbitrary code in some of the dynamically generated Web pages or perform cross-site scripting attacks against the target router. |
| Attack Detection: | Users of VPN-1 NG with Application Intelligence R54, R55 and R55W and users of VPN-1 NGX R60 should update their SmartDefense by clicking Online Update (R55- Update Now) in the SmartDashboard General window. |
| Solution: | Users of VPN-1 NG with Application Intelligence R55 & R55W and users of VPN-1 NGX R60 should update their SmartDefense by clicking Online Update (R55 - Update now) in the SmartDashboard General window. Users of R54, R55: |
| Industry Reference: | CVE-2005-3921 |
| Additional Information: |
This update also includes: |