CVE-2011-1646
Summary
| CVE | CVE-2011-1646 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-05-31 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Rvs4000 | 1 | All | All | All |
| Hardware | Cisco | Rvs4000 | 2 | All | All | All |
| Application | Cisco | Rvs4000 Software | 1.3.0.5 | All | All | All |
| Application | Cisco | Rvs4000 Software | 1.3.1.0 | All | All | All |
| Application | Cisco | Rvs4000 Software | 1.3.2.0 | All | All | All |
| Application | Cisco | Rvs4000 Software | 2.0.0.3 | All | All | All |
| Hardware | Cisco | Wrvs4400n | 1.0 | All | All | All |
| Hardware | Cisco | Wrvs4400n | 1.1 | All | All | All |
| Hardware | Cisco | Wrvs4400n | 2 | All | All | All |
| Application | Cisco | Wrvs4400n Software | 1.3.0.5 | All | All | All |
| Application | Cisco | Wrvs4400n Software | 1.3.1.0 | All | All | All |
| Application | Cisco | Wrvs4400n Software | 1.3.2.0 | All | All | All |
| Application | Cisco | Wrvs4400n Software | 2.0.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Systems - Redirect to | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| Cisco Gigabit Security Router Bugs Let Remote Users Obtain Information and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.