Skip to content
COOEY

EXPOSURES › CVE-2008-4128

CVE-2008-4128

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2008-4128 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedsupply-chain

Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution.

This CVE allows remote attackers to execute arbitrary commands on Cisco IOS 12.4 devices through specific HTTP URIs, posing a severe risk to DIB networks relying on legacy or unpatched Cisco hardware. Organizations must immediately audit their Cisco IOS inventory for version 12.4 and apply patches to prevent unauthorized access and potential data exfiltration.

Shame score — Active exploitation of a known vulnerability in widely deployed Cisco hardware indicates a failure in vendor patch management and DIB vendor oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized