PT-2017-17191 · Cisco · Cvr100W Wireless-N Vpn Router

Publicado

2017-05-03

·

Atualizado

2019-10-03

·

CVE-2017-6620

CVSS v3.1

5.8

Média

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco CVR100W Wireless-N VPN Router versions prior to 1.0.1.24
Description A vulnerability in the remote management access control list (ACL) feature could allow an unauthenticated, remote attacker to bypass the remote management ACL. This is due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. An attacker could exploit this by sending a connection to the management IP address or domain name of the targeted device, potentially allowing them to bypass the configured remote management ACL. This issue can occur even when the Remote Management configuration parameter is set to Disabled.
Recommendations For Cisco CVR100W Wireless-N VPN Router versions prior to 1.0.1.24, update the firmware to version 1.0.1.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the remote management interface until the update can be applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6620

Produtos afetados

Cvr100W Wireless-N Vpn Router