This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote device is missing a vendor-supplied security patch.
A vulnerability exists in the Cisco IOS Software that may allow a
remote application or device to exceed its authorization level when
authentication, authorization, and accounting (AAA) authorization is
used. This vulnerability requires that the HTTP or HTTPS server is
enabled on the Cisco IOS device. Products that are not running Cisco
IOS Software are not vulnerable. Cisco has released free software
updates that address these vulnerabilities. The HTTP server may be
disabled as a workaround for the vulnerability described in this
See also :
Apply the relevant patch referenced in Cisco Security Advisory
Risk factor :
High / CVSS Base Score : 8.5
CVSS Temporal Score : 6.3
Public Exploit Available : false
Nessus Plugin ID: 58570 ()
Bugtraq ID: 52755
CVE ID: CVE-2012-0384
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.