The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
| Software | From | Fixed in |
|---|---|---|
| cisco / catalyst_3500_xl | - | - |