Lucene search

K
cveCiscoCVE-2021-1287
HistoryMar 18, 2021 - 7:15 p.m.

CVE-2021-1287

2021-03-1819:15:13
CWE-121
cisco
web.nvd.nist.gov
43
4
cisco
rv132w
rv134w
vulnerability
remote attacker
arbitrary code
device restart
dos
nvd
cve-2021-1287

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.4%

A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition on the affected device.

Affected configurations

Nvd
Node
ciscorv132w_firmwareRange<1.0.1.15
AND
ciscorv132wMatch-
Node
ciscorv134w_firmwareRange<1.0.1.21
AND
ciscorv134wMatch-
VendorProductVersionCPE
ciscorv132w_firmware*cpe:2.3:o:cisco:rv132w_firmware:*:*:*:*:*:*:*:*
ciscorv132w-cpe:2.3:h:cisco:rv132w:-:*:*:*:*:*:*:*
ciscorv134w_firmware*cpe:2.3:o:cisco:rv134w_firmware:*:*:*:*:*:*:*:*
ciscorv134w-cpe:2.3:h:cisco:rv134w:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Small Business RV Series Router Firmware",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

Social References

More

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.4%