CVE-2007-2586 Details
Description
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios | 12.0(1)t 12.0(1)t1 12.0(1)xe 12.0(2)s 12.0(2)t 12.0(2)t1 12.0(2)xe 12.0(2)xe1 12.0(2)xe3 12.0(2)xe4 12.0(2a)t1 12.0(3)s 12.0(3)t 12.0(3)t2 12.0(3)t3 12.0(4)s 12.0(4)t 12.0(4)xe 12.0(4)xe2 12.0(5)s 12.0(5)t 12.0(5)t1 12.0(5)xe 12.0(5)xe1 12.0(5)xe2 12.0(5)xe3 12.0(5)xe4 12.0(5)xe5 12.0(5)xe8 12.0(5)xk 12.0(5)xk1 12.0(5)xk2 12.0(5)xt1 12.0(6)s 12.0(6)s1 12.0(6)s2 12.0(7)s 12.0(7)s1 12.0(7)t 12.0(7)t1 12.0(7)t2 12.0(7)t3 12.0(7)xk 12.0(7)xk1 12.0(7)xk2 12.0(7)xk3 12.0(8)s 12.0(8)s1 12.0(9)s 12.0(9)s8 12.0(9)st 12.0(10)s 12.0(10)s1 12.0(10)s2 12.0(10)s3 12.0(10)s3b 12.0(10)s4 12.0(10)s5 12.0(10)s6 12.0(10)s7 12.0(10)s8 12.0(10)st 12.0(10)st1 12.0(10)st2 12.0(11)s 12.0(11)s1 12.0(11)s2 12.0(11)s3 12.0(11)s4 12.0(11)s5 12.0(11)s6 12.0(11)st 12.0(11)st1 12.0(11)st2 12.0(11)st3 12.0(11)st4 12.0(28)s4a 12.0(31)sz2 12.1(3)xi 12.1(5)xm 12.1(5)xm1 12.1(5)xm2 12.1(5)xm3 12.1(5)xm4 12.1(5)xm5 12.1(5)xm7 12.1(5)xm8 12.1(5c)ex 12.1(5c)ex1 12.1(6)ex 12.1(8b)ex4 12.1(9)ex 12.2(8)zb 12.2(9)yo 12.2(9)yo1 12.2(9)yo2 12.2(9)yo3 12.2(9)yo4 12.2(11)yz 12.2(11)yz1 12.2(11)yz2 12.2(11)yz3 12.2(12b)m1 12.2(12h)m1 12.2(13)zf 12.2(13)zf1 12.2(13)zf2 12.2(13)zh 12.2(13)zh1 12.2(13)zh2 12.2(13)zh3 12.2(13)zh4 12.2(13)zh5 12.2(13b)m1 12.2(13b)m2 12.2(14)sz 12.2(14)sz1 12.2(14)sz2 12.2(14)sz3 12.2(14)sz4 12.2(14)sz5 12.2(14)sz6 12.2(15)zj 12.2(15)zj1 12.2(15)zj2 12.2(15)zj3 12.2(15)zj4 12.2(15)zj5 12.2(15)zl 12.2(15)zl1 12.2(15)zn 12.2(18)s 12.2(18)s1 12.2(18)s2 12.2(18)s3 12.2(18)s4 12.2(20)s 12.2(20)s1 12.2(20)s2 12.2(20)s2a 12.2(20)s3 12.2(20)s4 12.2(20)s4a 12.2(20)s5 12.2(20)s6 12.2(22)s 12.2(25)s 12.2(25)s1 12.2(25)s2 12.2(25)se 12.3(1a)b 12.3(2)ja3 12.3(2)ja4 12.3(2)t 12.3(2)t1 12.3(2)t2 12.3(2)t3 12.3(2)t4 12.3(2)t5 12.3(2)t6 12.3(2)t7 12.3(2)t8 12.3(2)t9 12.3(2)xa 12.3(2)xa1 12.3(2)xa2 12.3(2)xa3 12.3(2)xa4 12.3(2)xa5 12.3(2)xc 12.3(2)xc1 12.3(2)xc2 12.3(2)xe 12.3(2)xe1 12.3(2)xe2 12.3(2)xe3 12.3(2)xe4 12.3(2)xf 12.3(3)b 12.3(3)b1 12.3(4)t 12.3(4)t1 12.3(4)t2 12.3(4)t3 12.3(4)t4 12.3(4)t5 12.3(4)t6 12.3(4)t7 12.3(4)t8 12.3(4)t9 12.3(4)t10 12.3(4)t11 12.3(4)tpc11a 12.3(4)xd 12.3(4)xd1 12.3(4)xd2 12.3(4)xd3 12.3(4)xd4 12.3(4)xg 12.3(4)xg1 12.3(4)xg2 12.3(4)xg3 12.3(4)xg4 12.3(4)xg5 12.3(4)xh 12.3(4)xh1 12.3(4)xk 12.3(4)xk1 12.3(4)xk2 12.3(4)xk3 12.3(4)xk4 12.3(4)xq 12.3(4)xq1 12.3(4)ye 12.3(4)ye1 12.3(5a)b 12.3(5a)b0a 12.3(5a)b1 12.3(5a)b2 12.3(5a)b3 12.3(5a)b4 12.3(5a)b5 12.3(7)jx9 12.3(7)t 12.3(7)t1 12.3(7)t2 12.3(7)t3 12.3(7)t4 12.3(7)t6 12.3(7)t7 12.3(7)t8 12.3(7)t9 12.3(7)t10 12.3(7)t11 12.3(7)t12 12.3(7)xi3a 12.3(7)xl 12.3(7)xr 12.3(7)xr1 12.3(7)xr2 12.3(7)xr3 12.3(7)xr4 12.3(7)xr5 12.3(7)xr6 12.3(7)xs 12.3(7)xs1 12.3(7)xs2 12.3(8)jk 12.3(8)t 12.3(8)t1 12.3(8)t2 12.3(8)t3 12.3(8)t4 12.3(8)t5 12.3(8)t6 12.3(8)t7 12.3(8)t8 12.3(8)t9 12.3(8)t10 12.3(8)t11 12.3(8)xx 12.3(8)xx1 12.3(8)xx2 12.3(8)xx2a 12.3(8)xx2b 12.3(8)xx2c 12.3(8)ya 12.3(8)ya1 12.3(8)yc 12.3(8)yc1 12.3(8)yc2 12.3(8)yc3 12.3(8)yd 12.3(8)yd1 12.3(8)yg 12.3(8)yg1 12.3(8)yg2 12.3(8)yg3 12.3(8)yg4 12.3(8)yg5 12.3(8)yh 12.3(8)yi 12.3(8)yi1 12.3(8)yi2 12.3(8)yi3 12.3(8)za 12.3(9)m0 12.3(9)m1 12.3(10a)m0 12.3(11)ja2 12.3(11)jx 12.3(11)jx1 12.3(11)t 12.3(11)t1 12.3(11)t2 12.3(11)t3 12.3(11)t4 12.3(11)t5 12.3(11)t6 12.3(11)t7 12.3(11)t8 12.3(11)t9 12.3(11)t10 12.3(11)t11 12.3(11)to3 12.3(11)xl 12.3(11)xl1 12.3(11)xl2 12.3(11)xl3 12.3(11)yf2 12.3(11)yk 12.3(11)yk1 12.3(11)yk2 12.3(11)yl 12.3(11)yl1 12.3(11)yl2 12.3(11)ys 12.3(11)ys1 12.3(11)yz 12.3(11)yz1 12.3(11)zb 12.3(11)zb1 12.3(14)t 12.3(14)t1 12.3(14)t2 12.3(14)t3 12.3(14)t4 12.3(14)t5 12.3(14)t6 12.3(14)t7 12.3(14)ym2 12.3(14)ym3 12.3(14)ym4 12.3(14)ym5 12.3(14)ym6 12.3(14)ym7 12.3(14)ym8 12.3(14)ym9 12.3(14)yt 12.3(14)yt1 12.4(2)t 12.4(2)t1 12.4(2)t2 12.4(2)t3 12.4(2)t4 12.4(2)t5 12.4(2)xa 12.4(2)xa1 12.4(2)xa2 12.4(4)t 12.4(4)t1 12.4(4)t2 12.4(4)t3 12.4(4)t4 12.4(4)t5 12.4(4)xc 12.4(4)xc1 12.4(4)xc2 12.4(4)xc3 12.4(4)xc4 12.4(4)xc5 12.4(4)xd 12.4(4)xd1 12.4(4)xd2 12.4(4)xd3 12.4(5a)m0 12.4(6)t 12.4(6)t1 12.4(6)t2 12.4(6)t3 12.4(6)t4 12.4(6)t5 12.4(6)xe 12.4(6)xe1 12.4(6)xe2 12.4(9)t 12.4(9)t0a 12.4(9)t1 12.4(11)sw 12.4(11)sw1 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 9, 2023 | Reanalysis | [email protected] |
| May 22, 2020 | Modified Analysis | [email protected] |
| Oct 11, 2017 | CVE Modified | [email protected] |
| Jul 29, 2017 | CVE Modified | [email protected] |
| May 10, 2007 | Initial Analysis | [email protected] |