cve-2008-4128
HIGH CVSS 8.1 opencve
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
Timeline
- Published
- 2008-09-18 20:00 UTC
- Last Modified
- 2026-09-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
nvd | ||
| 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
opencve | ||
| 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
vulnrichment |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"advisories": [
{
"id": "EUVD-2008-4111",
"source": "euvd",
"title": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.",
"url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-4111"
}
],
"cve": "CVE-2008-4128",
"epss": {
"score": 0.33917
},
"kev": {
"dateAdded": "2026-07-13T00:00:00+00:00",
"dueDate": "2026-07-16T00:00:00+00:00"
},
"mitre": {
"cpes": [],
"created": "2008-09-18T20:00:00+00:00",
"description": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2008/4xxx/CVE-2008-4128.json",
"references": [
"http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html",
"http://www.securityfocus.com/bid/31218",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/45226",
"https://www.exploit-db.com/exploits/6476",
"https://www.exploit-db.com/exploits/6477"
],
"title": null,
"updated": "2026-09-23T18:10:24.249000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:h:cisco:871_integrated_services_router:-:*:*:*:*:*:*:*",
"cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
],
"created": "2008-09-18T20:00:00.530000+00:00",
"description": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.",
"metrics": {
"cvssV2_0": {
"score": 9.3,
"vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.1,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2008/CVE-2008-4128.json",
"references": [
"http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html",
"http://www.securityfocus.com/bid/31218",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/45226",
"https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128",
"https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html",
"https://www.exploit-db.com/exploits/6476",
"https://www.exploit-db.com/exploits/6477"
],
"title": null,
"updated": "2026-09-23T19:17:25.597000+00:00",
"vendors": [
"cisco",
"cisco$PRODUCT$871_integrated_services_router",
"cisco$PRODUCT$ios"
],
"weaknesses": [
"CWE-352"
]
},
"opencve": {
"changes": [
{
"created": "2026-07-13T17:15:00+00:00",
"data": [
{
"details": {
"added": {
"kev": {
"dateAdded": "2026-07-13T00:00:00+00:00",
"dueDate": "2026-07-16T00:00:00+00:00"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "6607c669-95b5-484c-9837-19b403bca058"
},
{
"created": "2026-07-13T18:30:00+00:00",
"data": [
{
"details": {
"added": [
"https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128",
"https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "8113b0a5-3553-4c0f-8aed-7e746c639da6"
},
{
"created": "2026-09-23T19:30:00+00:00",
"data": [
{
"details": {
"added": {},
"removed": {},
"updated": {
"cvssV3_1": {
"new": {
"score": 8.1,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
},
"old": {
"score": 4.3,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"
}
},
"ssvc": {
"new": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"old": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
}
}
},
"type": "metrics"
}
],
"id": "77e8d9b9-e92e-4523-8d82-bac38e7bb2a3"
}
],
"cpes": {
"data": [
"cpe:2.3:h:cisco:871_integrated_services_router:-:*:*:*:*:*:*:*",
"cpe:2.3:o:cisco:ios:12.4:*:*:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2008-09-18T20:00:00+00:00",
"provider": "mitre"
},
"description": {
"data": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {
"score": 9.3,
"vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
},
"provider": "nvd"
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 8.1,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
},
"provider": "vulnrichment"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.33917
},
"provider": "first"
},
"kev": {
"data": {
"dateAdded": "2026-07-13T00:00:00+00:00",
"dueDate": "2026-07-16T00:00:00+00:00"
},
"provider": "cisa"
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html",
"http://www.securityfocus.com/bid/31218",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/45226",
"https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128",
"https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html",
"https://www.exploit-db.com/exploits/6476",
"https://www.exploit-db.com/exploits/6477"
],
"providers": [
"mitre",
"nvd",
"vulnrichment"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-09-23T19:17:25.597000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"cisco",
"cisco$PRODUCT$871_integrated_services_router",
"cisco$PRODUCT$ios"
],
"providers": [
"nvd"
]
},
"weaknesses": {
"data": [
"CWE-352"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2008-09-18T20:00:00+00:00",
"description": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain \"show privilege\" command to the /level/15/exec/- URI, and (2) a certain \"alias exec\" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.1,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
},
"cvssV4_0": {},
"kev": {
"dateAdded": "2026-07-13"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [
"https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128",
"https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html"
],
"title": null,
"updated": "2026-07-13T13:10:28.638000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2008/4xxx/CVE-2008-4128.json",
"weaknesses": [
"CWE-352"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)