HTTP: Cisco Scanner Probe

This signature detects connections by the "Cisco Scanner" exploitation tool that searches for Cisco routers' HTTP administration interfaces and attempts to exploit them. Numerous vulnerabilities in the HTTP interface allow remote attackers complete control of the router.

Extended Description

IOS is router firmware developed and distributed by Cisco Systems. IOS functions on numerous Cisco devices, including routers and switches. It is possible to gain full remote administrative access on devices using affected releases of IOS. By using a URL of http://router.address/level/$NUMBER/exec/.... where $NUMBER is an integer between 16 and 99, it is possible for a remote user to gain full administrative access. This problem makes it possible for a remote user to gain full administrative privileges, which may lead to further compromise of the network or result in a denial of service.

Affected Products

Cisco ios

Short Name
HTTP:CISCO:SCANNER-PROBE
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CA-2001-14 CVE-2001-0537 Cisco Probe Scanner bid:2936
Release Date
03/09/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3727
False Positive
Unknown
Vendors

Cisco

CVSS Score

9.3

Found a potential security threat?