Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6620

Опубликовано: 03 мая 2017
Источник: nvd
CVSS3: 5.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. An attacker could exploit this vulnerability by sending a connection to the management IP address or domain name of the targeted device. A successful exploit could allow the attacker to bypass the configured remote management ACL. This can occur when the Remote Management configuration parameter is set to Disabled. This vulnerability affects Cisco CVR100W Wireless-N VPN Routers running a firmware image prior to 1.0.1.24. Cisco Bug IDs: CSCvc14457.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:small_business_rv_series_router_firmware:1.0.1.19:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_rv_series_router:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00161
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-264
CWE-20

Связанные уязвимости

CVSS3: 5.8
github
больше 3 лет назад

A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. An attacker could exploit this vulnerability by sending a connection to the management IP address or domain name of the targeted device. A successful exploit could allow the attacker to bypass the configured remote management ACL. This can occur when the Remote Management configuration parameter is set to Disabled. This vulnerability affects Cisco CVR100W Wireless-N VPN Routers running a firmware image prior to 1.0.1.24. Cisco Bug IDs: CSCvc14457.

EPSS

Процентиль: 37%
0.00161
Низкий

5.8 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-264
CWE-20