Cyber Resilience

CVE-2008-4128

CSRF in Cisco Ios 12.4

CISA KEVActive ExploitationPublic PoCCSRF
Published
18 September 2008
Modified
14 July 2026
KEV Added
13 July 2026
Patch / advisory
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score 0.33 98th percentile
Risk Priority 60 floored blend · peak EPSS

Summary

CVE-2008-4128 is a medium-severity CSRF (CWE-352) vulnerability in Cisco Ios. Its CVSS base score is 4.3 (Medium).

Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and…

more

(2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

CWE(s)
KEV Date Added
13 July 2026

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
CSRF in the public HTTP admin interface directly enables remote command execution on the device.
T1059.008 Network Device CLI Executionconfidence: MEDIUM
Vulnerability permits execution of arbitrary IOS CLI commands (e.g., show/alias exec) via the web interface.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2024-20414Same product: Cisco Ios
CVE-2024-20254Same vendor: Cisco
CVE-2024-20368Same vendor: Cisco
CVE-2024-20437Same vendor: Cisco
CVE-2024-20486Same vendor: Cisco
CVE-2024-20347Same vendor: Cisco
CVE-2023-20113Same vendor: Cisco
CVE-2023-20180Same vendor: Cisco
CVE-2024-20252Same vendor: Cisco
CVE-2025-20326Same vendor: Cisco

Affected Assets

cisco
ios
12.4

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.3.2
  • V3.5.1
  • V10.2.1

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-352

Awareness training educates users on avoiding untrusted links and actions that can be exploited via CSRF.

addresses: CWE-352

Requiring user re-entry of credentials for sensitive actions prevents automated forgery of requests without active user participation.

addresses: CWE-352

Security testing regimens explicitly include checks for missing or ineffective anti-CSRF protections in web applications.

addresses: CWE-352

Detects anomalous request patterns consistent with cross-site request forgery.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly require anti-CSRF controls such as tokens or SameSite attributes.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

mitigates

By denying access to phishing or malicious sites, the control lowers the likelihood that a user will be tricked into submitting a forged request that performs an unintended action on another site.

none

Contextual intelligence about emerging CSRF toolkits can be translated into updated anti-CSRF token or same-site policy configurations across applications.

References