← Vulnerability feed

Vulnerability record · CVE-2001-0537 · published 21 July 2001

CVE-2001-0537: Cisco IOS HTTP server authentication bypass via URL access level

Cisco · Ios

The HTTP server in Cisco IOS 11.3 through 12.2 fails to properly enforce local authorization, letting a remote attacker bypass authentication by specifying a high access level in the URL. Successful abuse grants full command execution on the device, making it a complete compromise of the router or switch.

9.3 CVSS 2.0 High EPSS 68% · top 0.7% CWE-287 · Improper authentication
9.3CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution on network infrastructure with complete impact and very high EPSS, despite the absence of KEV listing.

What it is

The HTTP server in Cisco IOS 11.3 through 12.2 fails to properly enforce local authorization, letting a remote attacker bypass authentication by specifying a high access level in the URL. Successful abuse grants full command execution on the device, making it a complete compromise of the router or switch.

Impact

An attacker gains full read and write control of the affected device, including the ability to run arbitrary IOS commands, alter configuration, and pivot into the network. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reachable over the network through the IOS HTTP server when local authorization is enabled; no credentials are required per the vector (Au:N), though the attack complexity is rated medium. No user interaction is described.

Exploitation

The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.6845 (99.3rd percentile) and multiple references carry an Exploit tag, indicating public exploit material exists.

What to do

  • Apply the Cisco patch referenced in the vendor advisory for the affected IOS release.
  • Disable the IOS HTTP server (no ip http server) where it is not operationally required.
  • Restrict management-plane access to trusted hosts with ACLs and out-of-band management.
  • Replace local authorization with centralized AAA (TACACS+/RADIUS) if the HTTP server must remain enabled.
  • Audit device configurations for exposed HTTP services and unexpected privilege levels.

Detection

  • Monitor IOS HTTP server logs and syslog for requests containing unusual access-level parameters in the URL.
  • Alert on configuration changes or privileged command execution originating from HTTP sessions.
  • Baseline and review devices with the HTTP server enabled and local authorization in use.
  • Watch for anomalous management-plane traffic to TCP/80 on IOS devices from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.cert.org/advisories/CA-2001-14.html ExploitPatchThird Party AdvisoryUS Government Resource
http://www.ciac.org/ciac/bulletins/l-106.shtml
http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html ExploitPatchVendor Advisory
http://www.osvdb.org/578
http://www.securityfocus.com/archive/1/1601227034.20010702112207%40olympos.org
http://www.securityfocus.com/archive/1/20010703011650.60515.qmail%40web14910.mail.yahoo.com
http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70%40brussels.cisco.com
http://www.securityfocus.com/archive/1/Pine.LNX.3.96.1010702134611.22995B-100000%40Lib-Vai.lib.asu.edu
http://www.securityfocus.com/bid/2936 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/6749
http://www.cert.org/advisories/CA-2001-14.html ExploitPatchThird Party AdvisoryUS Government Resource
http://www.ciac.org/ciac/bulletins/l-106.shtml
http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html ExploitPatchVendor Advisory
http://www.osvdb.org/578
http://www.securityfocus.com/archive/1/1601227034.20010702112207%40olympos.org
http://www.securityfocus.com/archive/1/20010703011650.60515.qmail%40web14910.mail.yahoo.com
http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70%40brussels.cisco.com
http://www.securityfocus.com/archive/1/Pine.LNX.3.96.1010702134611.22995B-100000%40Lib-Vai.lib.asu.edu
http://www.securityfocus.com/bid/2936 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/6749

Track CVE-2001-0537 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2001-0537), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.