Knox CVE Database
/
CVE-2008-4128
Medium
4.3

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Added to the CISA KEV catalog:
July 13, 2026

Overview

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

Vulnerability details

Affected vendor
Cisco
Affected product
IOS
Weakness type (CWE)
CWE-352

This vulnerability is a cross-site request forgery (CWE-352) affecting the HTTP administration component of Cisco IOS 12.4. The embedded web management interface exposes privileged EXEC functionality through URIs such as /level/15/exec/-, which accept state-changing commands via simple GET requests without verifying that the request originated from an intentional, user-initiated action within the management application. Because the browser automatically attaches the authenticated session's credentials (cookie or HTTP Basic auth) to any request it sends, the router cannot distinguish a legitimate administrative click from a request triggered by a malicious page the administrator happens to have open.

If an authenticated administrator's browser is induced to load attacker-controlled content (an image tag, hidden form, or redirect referencing the vulnerable URIs), the router will execute the embedded command with level-15 privilege, as demonstrated by the "show privilege" and "alias exec" cases. The "alias exec" path is particularly severe, since it can be used to define persistent command aliases that later execute arbitrary IOS configuration changes. The CVSS vector confirms the realistic path: network-reachable (AV:N), low attack complexity, no attacker privileges required, but contingent on user interaction — an administrator with an active HTTP management session must visit or be served the malicious content.

Severity and impact

4.3
Medium
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality impact
Low
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review IOS HTTP server access logs for GET requests to /level/15/exec/ URIs where the Referer header is absent or points to an external, non-management domain.
  • Audit running-config and configuration archives for unexpected "alias exec" entries, especially aliases that were not introduced through change-controlled processes.
  • Enable AAA command accounting (aaa accounting commands) to log all EXEC-level commands with source session details, and alert on privileged commands issued outside known maintenance windows.
  • Correlate HTTP management interface session timestamps with administrator activity records to flag command execution that doesn't match expected admin behavior.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 16, 2026

Additional hardening

  • Disable the IOS HTTP/HTTPS server (no ip http server / no ip http secure-server) on devices where web-based management is not explicitly required.
  • Restrict access to the HTTP management interface with access control lists limiting connections to a dedicated management VLAN or hardened jump hosts.
  • Prefer SSH-based CLI management over the HTTP administration interface, since CSRF is inherently a browser-session attack vector.
  • Enforce short idle timeouts on authenticated HTTP management sessions and instruct administrators to avoid general web browsing while a privileged router session is active.

Key dates

Published (NVD)
September 18, 2008
Added to CISA KEV
July 13, 2026
Remediation deadline
July 16, 2026
Last updated
July 14, 2026

References

Frequently asked questions

Does CVE-2008-4128 affect my FedRAMP authorization?

If Cisco IOS runs inside your authorization boundary, yes. CVE-2008-4128 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 16, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2008-4128?

Knox doesn't patch your software for you — remediating Cisco IOS is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2008-4128 isn't remediated by July 16, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting