Executive Summary
Summary | |
---|---|
Title | Cisco RV180 VPN and RV180W Wireless-N Multifunction VPN Routers Unauthorized Access Vulnerability |
Informations | |||
---|---|---|---|
Name | cisco-sa-20160803-rv180_1 | First vendor Publication | 2016-08-03 |
Vendor | Cisco | Last vendor Modification | 2016-08-03 |
Severity (Vendor) | N/A | Revision | 1.0 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability in the web interface of the Cisco RV180 VPN Router and Cisco RV180W Wireless-N Multifunction VPN Router could allow an unauthenticated, remote attacker to access arbitrary files on the system. This vulnerability allows the attacker to perform directory traversal. The vulnerability is due to lack of proper input verification and sanitization of the user input directory path. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. An exploit could allow the attacker to read arbitrary files on the system that should be restricted. Cisco has not released and will not release a firmware update to address this vulnerability. Mitigations for this vulnerability are available. This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-rv180_1 BEGIN PGP SIGNATURE Version: GnuPG v1.4.5 (SunOS) iQIVAwUBV5jida89gD3EAJB5AQJr1w//dQw1ljMBuVukQl7WC1BNN3A70yvaGilD ybcP5yDjJTfeB9jAoSzsM5UPmO1gyY/tF70EL9qyMhIiNxojpOadmypvrarqsA3J tuFosYDYKp67HAo075baCddODpJEmFtZM5WQEgFEL/+RIUakB9Rl9z8VYoTT+Qfx F+IYd3sBo/3fKh2Zk0ygDUZ1pPpTijMM8EpOKJlOJ8gYuiHny6fSngNdQMU1K1+A GtrMm1q2UOHrfa4U1UkH5Id2kVtLXTdaqtNZynp7JsuCdojhSQf1NkY8WRor0vmO LOk9AfgbZJvUGaO5Rym6GmlQDRAGy2AKUl2yhqGG6tS8JuHe20A8iVS9aCpwF+Hs YIFjzuKxitgFKGHllPBvv2Ue/v4/7sXP0EVhLNNqhdNIZj0PveEX4hnnfqAhe5YZ 6hWkxO7Qxmko8zujvgISpAUzL5TnJ1ACYg+mqZTt1tzz4LD3u/O0IHDvI9P37RYy 068EJrsG0swa9PCMxCBSdPc5GpeC8OZrDWYCh5LKy36hjv1qnshlHoYnHtyOcZul XKF88ASHF9kk7t9tYJBSdIM8tk17UKjk8nrKvz6dQd1cIJhcXqwJeN9X0GYBQ5d2 3gN4nhSLyKswG4nkahiSAzUUrLWadfUvqROVwJz4jHzDk5RDIEwAMHcMkDugq3ES MgxdW6yTuMY= =+uW1 END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com |
Original Source
Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...) |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 |
Snort® IPS/IDS
Date | Description |
---|---|
2016-08-04 | Cisco RV180 VPN Router platform.cgi directory traversal attempt RuleID : 39794 - Revision : 1 - Type : SERVER-WEBAPP |
2016-08-04 | Cisco RV180 VPN Router platform.cgi directory traversal attempt RuleID : 39793 - Revision : 1 - Type : SERVER-WEBAPP |
Alert History
Date | Informations |
---|---|
2016-08-11 21:24:54 |
|
2016-08-03 21:23:50 |
|