← Vulnerability feed

Vulnerability record · CVE-2007-2586 · published 10 May 2007

CVE-2007-2586: Cisco ios incorrect authorization vulnerability

Cisco · Ios

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

9.3 CVSS 2.0 High EPSS 14% · top 3.5% CWE-863 · Incorrect authorization
9.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/bugtraq/2009/Jan/0183.html Issue TrackingMailing ListThird Party Advisory
http://secunia.com/advisories/25199 Not ApplicableThird Party Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml Not Applicable
http://www.exploit-db.com/exploits/6155 ExploitThird Party AdvisoryVDB Entry
http://www.osvdb.org/35334 Broken Link
http://www.securityfocus.com/archive/1/494868 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/23885 Broken LinkExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018030 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/1749 Permissions RequiredThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34197 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5036 Broken LinkThird Party Advisory
http://seclists.org/bugtraq/2009/Jan/0183.html Issue TrackingMailing ListThird Party Advisory
http://secunia.com/advisories/25199 Not ApplicableThird Party Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml Not Applicable
http://www.exploit-db.com/exploits/6155 ExploitThird Party AdvisoryVDB Entry
http://www.osvdb.org/35334 Broken Link
http://www.securityfocus.com/archive/1/494868 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/23885 Broken LinkExploitThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018030 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/1749 Permissions RequiredThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34197 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5036 Broken LinkThird Party Advisory

Track CVE-2007-2586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2007-2586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.