Lucene search

K
cveCiscoCVE-2014-0683
HistoryMar 06, 2014 - 11:55 a.m.

CVE-2014-0683

2014-03-0611:55:05
CWE-255
cisco
web.nvd.nist.gov
63
cisco
rv110w
rv215w
cvr100w
firmware
authentication
access
vulnerability
nvd
cve-2014-0683

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.006

Percentile

77.6%

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to intercept requests, aka Bug IDs CSCul94527, CSCum86264, and CSCum86275.

Affected configurations

Nvd
Node
ciscorv110w_firmwareRange1.2.0.9
AND
ciscorv110wMatch-
Node
ciscorv215w_firmwareRange1.1.0.5
AND
ciscorv215wMatch-
Node
ciscocvr100w_firmwareRange1.0.1.19
AND
ciscocvr100wMatch-
VendorProductVersionCPE
ciscorv110w_firmware*cpe:2.3:o:cisco:rv110w_firmware:*:*:*:*:*:*:*:*
ciscorv110w-cpe:2.3:h:cisco:rv110w:-:*:*:*:*:*:*:*
ciscorv215w_firmware*cpe:2.3:o:cisco:rv215w_firmware:*:*:*:*:*:*:*:*
ciscorv215w-cpe:2.3:h:cisco:rv215w:-:*:*:*:*:*:*:*
ciscocvr100w_firmware*cpe:2.3:o:cisco:cvr100w_firmware:*:*:*:*:*:*:*:*
ciscocvr100w-cpe:2.3:h:cisco:cvr100w:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.006

Percentile

77.6%