CVE-2008-4128CISA KEVEPSS p98.4%
CVE-2008-4128Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco / IOS
Description
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
| EPSS | 33.87% probability of exploitation · percentile 98.4% · 2026-10-03T12:00:21Z |
| Last modified | 2026-09-24 |
CISA KEV entry
Added to KEV: 2026-07-13