Vulnslist

find the latest Cisco vulnerabilities

Cisco RV110W, RV130W, and RV215W Routers Management Interface Buffer Overflow Vulnerability

cisco-sa-20180905-rv-routers-overflow · Critical · Published · Updated

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-overflow

Workarounds

There are no workarounds that address this vulnerability. However, administrators may disable the Guest user account or remote management feature if not required.

CVEsCVE-2018-0423
Cisco Bug IDsCSCvj23206, CSCvj42729, CSCvj42727
CVSS ScoreBase 9.8
Base 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco RV130W Wireless-N Multifunction VPN Router Firmware, Cisco RV110W Wireless-N VPN Firewall Firmware, Cisco RV215W Wireless-N VPN Router Firmware

Related Products

Product CVE Evidence
Cisco RV110W Wireless-N VPN Firewall Firmware CVE-2018-0423 Cisco OpenVuln
Cisco RV130W Wireless-N Multifunction VPN Router Firmware CVE-2018-0423 Cisco OpenVuln
Cisco RV215W Wireless-N VPN Router Firmware CVE-2018-0423 Cisco OpenVuln
Cisco Small Business RV Series Router Firmware CVE-2018-0423 Cisco OpenVuln