Knox CVE Database
/
CVE-2008-4128
Critical
9.3

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain “show privilege” command to the /level/15/exec/- URI, and (2) a certain “alias exec” command to the /level/15/exec/-/configure/http URI.

Added to the CISA KEV catalog:
July 13, 2026

Overview

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain “show privilege” command to the /level/15/exec/- URI, and (2) a certain “alias exec” command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Vulnerability details

Affected vendor
Cisco
Affected product
IOS
Weakness type (CWE)
CWE-352

CVE-2008-4128 is a cross-site request forgery (CSRF) vulnerability in the HTTP Administration component of Cisco IOS 12.4 on the 871 Integrated Services Router. The router's HTTP management interface accepts POST requests to privileged URIs, including /level/15/exec/- and /level/15/exec/-/configure/http, without verifying that the request originated from a legitimate administrative session. Because the browser automatically attaches the administrator's credentials to any request directed at the router, a forged request is indistinguishable from a legitimate one at the server side.


An attacker crafts a web page containing a hidden HTML form that auto-submits on load, posting IOS commands such as 'show privilege' or 'alias exec' to the target router's level-15 management URIs. Two preconditions apply: the router's HTTP Administration component must be reachable, and a legitimate administrator with an active authenticated session must be socially engineered into visiting the attacker's page. When those conditions are met, the victim's browser delivers the forged POST with the admin's credentials, and the router executes the command at privilege level 15, granting the attacker full administrative control including configuration changes, credential disclosure, and denial of service.

Severity and impact

9.3
Critical
AV:N/AC:M/Au:N/C:C/I:C/A:C
Attack vector
Network
Attack complexity
Medium
Privileges required
User interaction
Scope
Confidentiality impact
Complete
Integrity impact
Complete
Availability impact
Complete

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review IOS HTTP access logs for POST requests to /level/15/exec/- or /level/15/exec/-/configure/http originating from source IP addresses that do not match known administrative workstations or management subnets.
  • Correlate HTTP server access records against authentication logs: a level-15 command execution with no corresponding interactive login from the same source address is a strong indicator of a forged request being processed.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 16, 2026

Additional hardening

  • Disable the IOS HTTP server entirely with 'no ip http server' if web-based management is not operationally required; use SSH-based CLI management instead.
  • Restrict HTTP administration access using an IOS access-class ACL that permits only explicitly defined management host addresses, blocking all other sources at the router.
  • Place the router's management interface on a dedicated out-of-band management network or VLAN that is not reachable from user workstations or the internet.
  • Require administrators to use dedicated, isolated management workstations for router access, reducing the likelihood that a browser on the same host visits untrusted web content during an active session.

Key dates

Published (NVD)
September 18, 2008
Added to CISA KEV
July 13, 2026
Remediation deadline
July 16, 2026
Last updated
July 14, 2026

References

Frequently asked questions

Does CVE-2008-4128 affect my FedRAMP authorization?

If Cisco IOS runs inside your authorization boundary, yes — this matters for your FedRAMP authorization. CVE-2008-4128 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 16, 2026. An unpatched KEV inside your boundary is an assessor finding: you either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it. The deadline is fixed; your response to it is not.

How does Knox help me handle CVE-2008-4128?

Remediating Cisco IOS is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that support your documentation at the next assessment. The fix belongs to your team; maintaining a compliant posture while you apply it is not something you have to manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance gaps, including exposures like CVE-2008-4128. That means issues surface during ongoing monitoring rather than only when an assessor flags them at review time, giving your team time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2008-4128 isn't remediated by July 16, 2026?

An unresolved CVE-2008-4128 past July 16, 2026 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization status clean and preserves the agency relationship that your federal contracts depend on.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting