CVE-2000-0945

CRITICAL ⚠ Exploit

The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing ...

Affects 1 product across 1 vendor.

BCS8.99
CVSS 2.010.0
EPSS72.6%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the web configuration interface of Catalyst 3500 XL switches allows unauthenticated remote attackers to execute arbitrary commands if the enable password is not set.

BSID: BS-2000-GLOBAL-309080-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2000-0945?
A critical vulnerability in the web configuration interface of Catalyst 3500 XL switches allows unauthenticated remote attackers to execute arbitrary commands if the enable password is not set.
What is the CVSS score for CVE-2000-0945?
CVE-2000-0945 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 72.6%.
Is CVE-2000-0945 actively exploited?
Public exploit available for CVE-2000-0945. Exploitation risk elevated.
How do I remediate CVE-2000-0945?
Priority: IMMEDIATE. Advisory: http://www.securityfocus.com/bid/1846 PSIRT: [email protected]
What systems are affected by CVE-2000-0945?
CVE-2000-0945 affects: Cisco.
Vulnerability Details
CVE IDCVE-2000-0945
BSIDBS-2000-GLOBAL-309080-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2000-12-19
Last Modified2026-04-16
ICS Relevance75%
Domains
NETWORK-INFRA
SourceNVD
Official Description

The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending a specially crafted URL containing the /exec/ directory to the web configuration interface of the switch. This URL can execute arbitrary commands on the device without requiring any authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Catalyst 3500 Xl
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 9349 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →