The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.879
EPSS Ranking 99.4%