← Back to browse · API

CVE-2008-4128

Severity
MEDIUM
CVSS
4.3
EPSS
0.32953
Risk score
53.73
CISA KEV
Yes
PoC
No
Published
2008-09-18
Modified
2026-07-14
First seen
2026-08-05
Aliases
EUVD-2008-4111, GHSA-6977-WJV6-R929
Products
Cisco:IOS, cisco:871_integrated_services_router, cisco:ios, n/a:n/a n/a
Sources
nvd CVE-2008-4128
euvd EUVD-2008-4111
cisa.gov CVE-2008-4128

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

References