PT-2019-2052 · Cisco · Cisco Small Business Rv325+1
Wu Linjie
+1
·
Publicado
2019-05-01
·
Atualizado
2021-09-13
·
CVE-2019-1724
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers (affected versions not specified)
Description
A vulnerability in the session management functionality of the web-based interface could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The attacker could use this impersonated session to create a new user account or control the device with the privileges of the hijacked session. This is due to a lack of proper session management controls. An attacker could exploit this by sending a crafted HTTP request to a targeted device, allowing them to take control of an existing user session if an authorized user session is active.
Recommendations
For Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers, as a temporary workaround, consider restricting access to the web-based interface until a patch is available. Avoid using the web-based interface for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Small Business Rv320
Cisco Small Business Rv325