CVE-2008-4128
Analyzed
Published: 18 Sept 2008, 20:00
Last modified:14 Jul 2026, 03:55
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
32.95% HIGH
33% probability +30.65%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected
Timeline
18 Sept 2008, 20:00
Published
Vulnerability first disclosed
13 Jul 2026, 00:00
Added to CISA KEV
Cisco IOS Cross-Site Request Forgery Vulnerability
14 Jul 2026, 03:55
Last Modified
Vulnerability information updated
16 Jul 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- v2.0•HIGH•Score: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 32.95%• Percentile: 98%
Techniques & Countermeasures
- CWE-352•Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Affected Systems
- cisco•ios
12.4
References (8)
- https://www.exploit-db.com/exploits/6476
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45226
- http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html
- https://www.exploit-db.com/exploits/6477
- http://www.securityfocus.com/bid/31218
- https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
- https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4128