CVE-2017-3882
Summary
| CVE | CVE-2017-3882 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-16 17:29:00 UTC |
| Updated | 2017-07-11 01:33:00 UTC |
| Description | A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Rv042 | - | All | All | All |
| Hardware | Cisco | Rv042 | - | All | All | All |
| Hardware | Cisco | Rv042g | - | All | All | All |
| Hardware | Cisco | Rv042g | - | All | All | All |
| Hardware | Cisco | Rv082 | - | All | All | All |
| Hardware | Cisco | Rv082 | - | All | All | All |
| Hardware | Cisco | Rv110w | - | All | All | All |
| Hardware | Cisco | Rv110w | - | All | All | All |
| Hardware | Cisco | Rv130 | - | All | All | All |
| Hardware | Cisco | Rv130 | - | All | All | All |
| Hardware | Cisco | Rv130w | - | All | All | All |
| Hardware | Cisco | Rv130w | - | All | All | All |
| Hardware | Cisco | Rv130w Wf | - | All | All | All |
| Hardware | Cisco | Rv130w Wf | - | All | All | All |
| Hardware | Cisco | Rv130 Wf | - | All | All | All |
| Hardware | Cisco | Rv130 Wf | - | All | All | All |
| Hardware | Cisco | Rv132w | - | All | All | All |
| Hardware | Cisco | Rv132w | - | All | All | All |
| Hardware | Cisco | Rv134w | - | All | All | All |
| Hardware | Cisco | Rv134w | - | All | All | All |
| Hardware | Cisco | Rv215w | - | All | All | All |
| Hardware | Cisco | Rv215w | - | All | All | All |
| Hardware | Cisco | Rv320 | - | All | All | All |
| Hardware | Cisco | Rv320 | - | All | All | All |
| Hardware | Cisco | Rv320 Wf | - | All | All | All |
| Hardware | Cisco | Rv320 Wf | - | All | All | All |
| Hardware | Cisco | Rv325 | - | All | All | All |
| Hardware | Cisco | Rv325 | - | All | All | All |
| Hardware | Cisco | Rv325 Wf | - | All | All | All |
| Hardware | Cisco | Rv325 Wf | - | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.0.30 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.1.19 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.1.9 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.2.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.3.10 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.39 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.4.10 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.4.14 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.4 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.4(gd) | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.4\(gd\) | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.5 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.8 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.6.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.0.30 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.1.19 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.1.9 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.2.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.3.10 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.39 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.4.10 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.4.14 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.4 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.4\(gd\) | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.5 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.5.8 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware | 1.0.6.6 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware 1.0 | 0.2 | All | All | All |
| Application | Cisco | Small Business Rv Router Firmware 1.0 | 0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco CVR100W Wireless-N VPN Router Buffer Overflow in UPnP Lets Remote Users on the Local Network Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Cisco CVR100W Wireless-N VPN Router CVE-2017-3882 Buffer Overflow Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco CVR100W Wireless-N VPN Router Universal Plug-and-Play Buffer Overflow Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.