This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Cisco First view 2014-11-07
Product rv180 Firmware Last view 2017-10-12
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:cisco:rv180_firmware:1.0.3.10:*:*:*:*:*:*:* 4
cpe:2.3:o:cisco:rv180_firmware:1.0.5.4:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
5.9 2017-10-12 CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.

5 2014-11-07 CVE-2014-2179

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.

6.8 2014-11-07 CVE-2014-2178

Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack the authentication of administrators, aka Bug ID CSCuh87145.

9 2014-11-07 CVE-2014-2177

The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.

CWE : Common Weakness Enumeration

%idName
25% (1) CWE-352 Cross-Site Request Forgery (CSRF)
25% (1) CWE-295 Certificate Issues
25% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
25% (1) CWE-20 Improper Input Validation

Snort® IPS/IDS

Date Description
2014-11-16 Cisco RV180W Router cross-site request forgery attempt
RuleID : 32398 - Type : SERVER-OTHER - Revision : 1
2014-06-21 Cisco RV180 VPN remote code execution attempt
RuleID : 30933 - Type : SERVER-OTHER - Revision : 5
2014-06-21 Cisco RV180W remote file inclusion attempt
RuleID : 30931 - Type : SERVER-OTHER - Revision : 5