Lucene search

K
cveCiscoCVE-2014-2179
HistoryNov 07, 2014 - 11:55 a.m.

CVE-2014-2179

2014-11-0711:55:02
CWE-20
cisco
web.nvd.nist.gov
26
cisco
rv router
firmware
remote file upload
http request
security vulnerability
cve-2014-2179

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

70.3%

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.

Affected configurations

Nvd
Node
ciscorv180_firmwareRange1.0.3.10
AND
ciscorv180Match-
OR
ciscorv180wMatch-
Node
ciscorv120w_firmwareRange1.0.5.8
AND
ciscorv120wMatch-
Node
ciscorv220w_firmwareRange1.0.5.8
AND
ciscorv220wMatch-
VendorProductVersionCPE
ciscorv180_firmware*cpe:2.3:o:cisco:rv180_firmware:*:*:*:*:*:*:*:*
ciscorv180-cpe:2.3:h:cisco:rv180:-:*:*:*:*:*:*:*
ciscorv180w-cpe:2.3:h:cisco:rv180w:-:*:*:*:*:*:*:*
ciscorv120w_firmware*cpe:2.3:o:cisco:rv120w_firmware:*:*:*:*:*:*:*:*
ciscorv120w-cpe:2.3:h:cisco:rv120w:-:*:*:*:*:*:*:*
ciscorv220w_firmware*cpe:2.3:o:cisco:rv220w_firmware:*:*:*:*:*:*:*:*
ciscorv220w-cpe:2.3:h:cisco:rv220w:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

70.3%