cisco-sa-20120223-srp500

Cisco Small Business SRP 500 Series Multiple Vulnerabilities

Critical · Updated · Cisco

3 products with CSAF evidence

Cisco Small Business (SRP 500) Series Services Ready Platforms contain the following three vulnerabilities: Cisco SRP 500 Series Web Interface Command Injection Vulnerability Cisco SRP 500 Series Unauthenticated Configuration Upload Vulnerability Cisco SRP 500 Series Directory Traversal Vulnerability These vulnerabilities can be exploited using sessions to the Services Ready Platform Configuration Utility web interface. These vulnerabilities could be exploited from the local LAN side of the SRP device by default configuration and the WAN side of the SRP device if remote management is enabled. Remote management is disabled by default. Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.