Vulnerability record · CVE-2000-0945 · published 19 December 2000
CVE-2000-0945: Cisco Catalyst 3500 XL web interface allows unauthenticated command execution
Cisco · Catalyst 3500 Xl
The web configuration interface on Catalyst 3500 XL switches exposes an /exec/ directory that lets remote attackers run arbitrary commands without authentication when no enable password is configured. Because the flaw yields full command execution on the switch, it matters for any deployment where the management interface is reachable and the enable password is unset.
Description
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with complete impact on a network device, combined with a very high EPSS score, warrants critical priority despite the absence of KEV listing.
What it is
The web configuration interface on Catalyst 3500 XL switches exposes an /exec/ directory that lets remote attackers run arbitrary commands without authentication when no enable password is configured. Because the flaw yields full command execution on the switch, it matters for any deployment where the management interface is reachable and the enable password is unset.
Impact
An attacker gains full control of the switch, including the ability to read and change configuration, disrupt network traffic, and use the device as a pivot into the network. The CVSS 2.0 vector (AV:N/AC:L/Au:N/C:C/I:C/A:C) reflects complete confidentiality, integrity and availability loss.
Attack surface
Reachable over the network through the switch's web configuration interface via a URL containing the /exec/ directory; no authentication is required and no user interaction is needed. The condition is that the enable password is not set.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high (0.72575, 99.4th percentile), indicating substantial predicted exploitation activity; references include vendor advisory and patch tags.
What to do
- Apply the vendor patch or upgrade referenced in the Cisco advisory and SecurityFocus BID 1846.
- Set a strong enable password on all Catalyst 3500 XL switches so the unauthenticated /exec/ path is not usable.
- Disable or restrict the web configuration interface, or block HTTP/HTTPS management access from untrusted networks.
- Isolate switch management interfaces on a dedicated management VLAN with strict ACLs.
- Audit all Catalyst 3500 XL devices for missing enable passwords and exposed web interfaces.
Detection
- Monitor web server logs on the switch for requests to the /exec/ directory, especially from unexpected source IPs.
- Alert on configuration changes or command execution events on switches that occur outside approved change windows.
- Scan the network for Catalyst 3500 XL web interfaces reachable from untrusted segments.
- Review authentication logs for management access without prior login, indicating unauthenticated command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0945 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0945), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.