CVE-2008-4128CISA KEVEPSS p98.4%

CVE-2008-4128Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco / IOS

Description

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Scoring

CVSS 8.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS33.87% probability of exploitation · percentile 98.4% · 2026-10-03T12:00:21Z
Last modified2026-09-24

CISA KEV entry

Added to KEV: 2026-07-13

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.