Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
BID:47984
Info
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
| Bugtraq ID: | 47984 |
| Class: | Design Error |
| CVE: |
CVE-2011-1646 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | Jun 17 2011 05:50PM |
| Credit: | Michal Sajdak of Securitum |
| Vulnerable: |
Cisco WRVS4400N Wireless-N Gigabit Security Router 2 Cisco WRVS4400N Wireless-N Gigabit Security Router 1.1 Cisco WRVS4400N Wireless-N Gigabit Security Router 1.0 Cisco RVS4000 4-port Gigabit Security Router 1.3.2 .0 Cisco RVS4000 4-port Gigabit Security Router 2 Cisco RVS4000 4-port Gigabit Security Router 1.3.0.3 Cisco RVS4000 4-port Gigabit Security Router 0 |
| Not Vulnerable: |
Cisco WRVS4400N Wireless-N Gigabit Security Router 2.0.2.1 Cisco RVS4000 4-port Gigabit Security Router 2.0.2.7 Cisco RVS4000 4-port Gigabit Security Router 1.3.3.5 |
Discussion
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
Cisco RVS4000 and WRVS4400N routers are prone to a remote command-injection vulnerability that affects their web-based management interface.
An authenticated attacker can exploit this issue to execute arbitrary commands with root-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug ID CSCtn23871.
Cisco RVS4000 and WRVS4400N routers are prone to a remote command-injection vulnerability that affects their web-based management interface.
An authenticated attacker can exploit this issue to execute arbitrary commands with root-level privileges on the underlying operating system.
This issue is being tracked by Cisco bug ID CSCtn23871.
Exploit / POC
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco RVS4000/WRVS4400N Web Management Interface Remote Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Cisco RVS4000 and WRVS4400N Web Management Interface Vu (Cisco Systems Product Security Incident Response Team
) - cisco-sa-20110525-rvs4000 Cisco Security Advisory: Cisco RVS4000 and WRVS4400N W (Cisco)