← Vulnerability feed

Vulnerability record · CVE-2007-1257 · published 3 March 2007

CVE-2007-1257: Cisco network analysis module improper input validation vulnerability

Cisco · Network Analysis Module

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

10.0 CVSS 2.0 High EPSS 6.8% · top 6.2% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2005-4258Cisco catalyst vulnerabilityUnspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and dest…EPSS 2.1%5.0CVE-2007-5134Cisco catalyst 6500 permissions and access controls vulnerabilityCisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might …EPSS 2.5%5.0CVE-2004-0551Cisco catos vulnerabilityCisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of se…EPSS 3.1%5.0CVE-2003-1001Cisco catalyst 6500 vulnerabilityBuffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial…EPSS 1.4%5.0CVE-2003-1002Cisco catalyst 6500 vulnerabilityCisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and …EPSS 1.3%9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2007-1257), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.