Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
BID:50495
Info
Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
| Bugtraq ID: | 50495 |
| Class: | Design Error |
| CVE: |
CVE-2011-4005 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2011 12:00AM |
| Updated: | Nov 02 2011 12:00AM |
| Credit: | Michal Sajdak of Securitum |
| Vulnerable: |
Cisco SRP547W 0 Cisco SRP546W 0 Cisco SRP541W 0 Cisco SRP527W 0 Cisco SRP526W 0 Cisco SRP521W 0 |
| Not Vulnerable: |
Cisco SRP547W 1.2.1 Cisco SRP546W 1.2.1 Cisco SRP541W 1.2.1 Cisco SRP541W 1.2.1 Cisco SRP527W 1.1.24 Cisco SRP526W 1.1.24 Cisco SRP521W 1.1.24 |
Discussion
Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
Cisco Small Business SRP500 Series Appliances are prone to a remote command-injection vulnerability.
Successful exploits will result in the execution of arbitrary attacker-supplied commands in the context of the root user. This may facilitate a complete compromise.
This issue is being tracked by Cisco bug ID CSCtr45124.
Cisco Small Business SRP500 Series Appliances are prone to a remote command-injection vulnerability.
Successful exploits will result in the execution of arbitrary attacker-supplied commands in the context of the root user. This may facilitate a complete compromise.
This issue is being tracked by Cisco bug ID CSCtr45124.
Exploit / POC
Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
The vendor reports that exploits for this issue are available.
The vendor reports that exploits for this issue are available.
Solution / Fix
Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco Small Business SRP500 Series Appliances Web Interface Remote Command Injection Vulnerability
References:
References: