Lucene search

K
nvd[email protected]NVD:CVE-2021-1602
HistoryAug 04, 2021 - 6:15 p.m.

CVE-2021-1602

2021-08-0418:15:08
CWE-20
CWE-78
web.nvd.nist.gov
4
cisco small business
vpn routers
vulnerability
unauthenticated
remote attackers
arbitrary commands

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

70.0%

A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device using root-level privileges. Due to the nature of the vulnerability, only commands without parameters can be executed.

Affected configurations

Nvd
Node
ciscosmall_business_rv_series_router_firmwareRange<1.0.01.04
AND
ciscosmall_business_rv160Match-
OR
ciscosmall_business_rv160wMatch-
OR
ciscosmall_business_rv260Match-
OR
ciscosmall_business_rv260pMatch-
OR
ciscosmall_business_rv260wMatch-
VendorProductVersionCPE
ciscosmall_business_rv_series_router_firmware*cpe:2.3:o:cisco:small_business_rv_series_router_firmware:*:*:*:*:*:*:*:*
ciscosmall_business_rv160-cpe:2.3:h:cisco:small_business_rv160:-:*:*:*:*:*:*:*
ciscosmall_business_rv160w-cpe:2.3:h:cisco:small_business_rv160w:-:*:*:*:*:*:*:*
ciscosmall_business_rv260-cpe:2.3:h:cisco:small_business_rv260:-:*:*:*:*:*:*:*
ciscosmall_business_rv260p-cpe:2.3:h:cisco:small_business_rv260p:-:*:*:*:*:*:*:*
ciscosmall_business_rv260w-cpe:2.3:h:cisco:small_business_rv260w:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

70.0%