Vulnslist

find the latest Cisco vulnerabilities

Cisco RV180 VPN and RV180W Wireless-N Multifunction VPN Routers Unauthorized Access Vulnerability

cisco-sa-20160803-rv180_1 · High · Published · Updated

A vulnerability in the web interface of the Cisco RV180 VPN Router and Cisco RV180W Wireless-N Multifunction VPN Router could allow an unauthenticated, remote attacker to access arbitrary files on the system. This vulnerability allows the attacker to perform directory traversal. The vulnerability is due to lack of proper input verification and sanitization of the user input directory path. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. An exploit could allow the attacker to read arbitrary files on the system that should be restricted. Cisco has not released and will not release a firmware update to address this vulnerability. Mitigations for this vulnerability are available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-rv180_1

Workarounds

There are no workarounds that address this vulnerability. The following two mitigations may help limit exposure to this vulnerability:

Disable Remote Management 

Caution: Do not disable remote management if the device is managed via the WAN connection. This will result in loss of management connectivity to the device. Disabling this feature prevents Cisco QuickVPN access.

Remote Management is disabled by default. If it is enabled, administrators can disable it using the Web Access screen: Administration > Management Interface > Web Access. Check the box for Disabled in the Remote Management field.

Disabling remote management helps ensure that only users on the LAN could attempt to exploit the vulnerabilities. Remote management is not enabled by default on the device.

Limit Remote Management Access to Specific IP Addresses

If remote management is required, harden the device so that it can be accessed only by certain IP addresses, rather than the default setting of any. By accessing the configuration screen (Administration > Management Interface > Web Access), an administrator can change the Remote IP address field to ensure only devices with specified IP addresses can access the device.

CVEsCVE-2016-1429
Cisco Bug IDsCSCuz43023
CVSS ScoreBase 7.1
Base 7.1 AV:N/AC:M/Au:N/C:C/I:N/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco RV180W Wireless-N Multifunction VPN Router Firmware, Cisco RV180 VPN Router

CSAF Product Statuses

Product Status Source CVE Rows
Cisco RV180 VPN Router known_affected cisco_csaf CVE-2016-1429 1
Cisco RV180W Wireless-N Multifunction VPN Router Firmware known_affected cisco_csaf CVE-2016-1429 1

Related Products

Product CVE Evidence
Cisco RV180 VPN Router CVE-2016-1429 Cisco OpenVuln
Cisco RV180W Wireless-N Multifunction VPN Router Firmware CVE-2016-1429 Cisco OpenVuln
Cisco Small Business RV Series Router Firmware CVE-2016-1429 Cisco OpenVuln