PT-2016-2273 · Cisco · Cisco Rv110W+2

Publicado

2016-06-19

·

Atualizado

2017-09-01

·

CVE-2016-1397

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco RV110W versions prior to 1.2.1.7 Cisco RV130W versions prior to 1.0.3.16 Cisco RV215W versions prior to 1.3.0.8
Description The issue is caused by a buffer overflow in the web-based management interface, allowing remote authenticated users to cause a denial of service (device reload) via crafted configuration commands in an HTTP request. This can be exploited by sending specially formed commands in an HTTP request.
Recommendations For Cisco RV110W versions prior to 1.2.1.7, update the firmware to version 1.2.1.7 or later. For Cisco RV130W versions prior to 1.0.3.16, update the firmware to version 1.0.3.16 or later. For Cisco RV215W versions prior to 1.3.0.8, update the firmware to version 1.3.0.8 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01637
CVE-2016-1397

Produtos afetados

Cisco Rv110W
Cisco Rv130W
Cisco Rv215W