PT-2018-8630 · Cisco · Cisco Rv134W+1

Publicado

2018-02-08

·

Atualizado

2020-09-04

·

CVE-2018-0127

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Cisco RV132W ADSL2+ Wireless-N VPN Routers (affected versions not specified) Cisco RV134W VDSL2 Wireless-AC VPN Routers (affected versions not specified)
Description: A vulnerability in the web interface could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, leading to the disclosure of confidential information. This is due to the absence of user authentication requirements for certain pages that contain confidential information. An attacker could exploit this by sending a crafted HTTP request to an affected device and examining the HTTP response. A successful exploit could allow the attacker to view configuration parameters, including the administrator password.
Recommendations: For Cisco RV132W ADSL2+ Wireless-N VPN Routers, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Cisco RV134W VDSL2 Wireless-AC VPN Routers, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0127

Produtos afetados

Cisco Rv132W
Cisco Rv134W