Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
BID:70921
Info
Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
| Bugtraq ID: | 70921 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2177 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2014 12:00AM |
| Updated: | Nov 24 2014 12:58AM |
| Credit: | Yorick Koster of Securify. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
Multiple Cisco RV Series Routers are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with root privileges in the context of the affected device.
This issue is being tracked by Cisco Bug ID CSCuh87126.
Multiple Cisco RV Series Routers are prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with root privileges in the context of the affected device.
This issue is being tracked by Cisco Bug ID CSCuh87126.
Exploit / POC
Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Cisco RV Series Routers CVE-2014-2177 Remote Command Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco )