Vulnerability Alert

Cisco IOS Software HTTP Request Processing Arbitrary Command Execution Vulnerability

Threat Type:CWE-78: OS Command Injections
IntelliShield ID:25363
First Published:2012 March 28 16:38 GMT
Last Published:2012 March 28 16:38 GMT
Port: Not available
Urgency:Unlikely Use
Severity:Moderate Damage
CVSS Base:9.0 CVSS Calculator
CVSS Version 2.0
CVSS Temporal:7.4
Version Summary:

Cisco IOS Software and Cisco IOS XE Software contain a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands. Updates are available.


Cisco IOS Software and Cisco IOS XE Software contain a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands.

The vulnerability is due to errors in the authentication, authorization, and accounting (AAA) authorization implementation when accessing an affected device via HTTP or HTTPS. An authenticated, remote attacker could exploit this vulnerability to execute arbitrary commands.

Cisco confirmed the vulnerability in a security advisory and released updated software.

Warning Indicators

Cisco has published a list of affected Cisco IOS Software and Cisco IOS XE Software releases in the security advisory. The Vendor Announcements section of this alert contains a link to the advisory.

IntelliShield Analysis

To exploit this vulnerability, the attacker would need to authenticate to the targeted device. To achieve this objective, the attacker may need access to trusted, internal network resources. This access requirement reduces the exposure of this vulnerability.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Vendor Announcements

Cisco has released a security advisory for Cisco bug ID CSCtr91106 at the following link: cisco-sa-20120328-pai


An authenticated, remote attacker could exploit this vulnerability to execute arbitrary commands in the security context of the user. Successful exploitation could result in a complete compromise of the targeted device.

Technical Information

The vulnerability is due to an error in the AAA authorization implementation. The error may allow the Cisco IOS Software command authorization to be bypassed when accessing an affected device with an HTTP or HTTPS session.

An authenticated, remote attacker could exploit this vulnerability to execute any arbitrary Cisco IOS Software commands configured for the privilege level of the user.


Administrators are advised to apply the appropriate updates.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected devices.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider disabling the HTTP and HTTPS server feature if it is not required.

Administrators are advised to monitor affected systems.


Cisco customers with active contracts can obtain updates through the Software Center at the following link: Cisco. Cisco customers without contracts can obtain upgrades by contacting the Cisco Technical Assistance Center at 1-800-553-2447 or 1-408-526-7209 or via e-mail at

Alert History

Initial Release

