CVE-2019-1898
Summary
| CVE | CVE-2019-1898 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-20 03:15:00 UTC |
| Updated | 2020-10-16 15:06:00 UTC |
| Description | A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file. |
Risk And Classification
Problem Types: CWE-425
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Rv110w | - | All | All | All |
| Hardware | Cisco | Rv110w | - | All | All | All |
| Operating System | Cisco | Rv110w Firmware | - | All | All | All |
| Operating System | Cisco | Rv110w Firmware | - | All | All | All |
| Hardware | Cisco | Rv130w | - | All | All | All |
| Hardware | Cisco | Rv130w | - | All | All | All |
| Operating System | Cisco | Rv130w Firmware | - | All | All | All |
| Operating System | Cisco | Rv130w Firmware | - | All | All | All |
| Hardware | Cisco | Rv215w | - | All | All | All |
| Hardware | Cisco | Rv215w | - | All | All | All |
| Operating System | Cisco | Rv215w Firmware | - | All | All | All |
| Operating System | Cisco | Rv215w Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Multiple Cisco Products CVE-2019-1898 Access Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco RV110W, RV130W, and RV215W Routers Multiple Vulnerabilities - Research Advisory | Tenable® | MISC | www.tenable.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.