PT-2017-16154 · Cisco · Cvr100W Wireless-N Vpn Router

Publicado

2017-05-16

·

Atualizado

2017-07-11

·

CVE-2017-3882

CVSS v3.1

9.6

Crítica

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco CVR100W Wireless-N VPN Router versions prior to 1.0.1.22
Description A vulnerability in the Universal Plug-and-Play (UPnP) implementation could allow an unauthenticated attacker to execute arbitrary code or cause a denial of service condition. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this by sending a malicious request to the UPnP listening port, potentially allowing the attacker to cause the device to reload or execute arbitrary code with root privileges.
Recommendations For versions prior to 1.0.1.22, update to Firmware Release 1.0.1.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the UPnP listening port to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3882

Produtos afetados

Cvr100W Wireless-N Vpn Router