CVE-2014-2177
 
Severity Score
9.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.
La interfaz de administración de la diagnostica de la red en el firmware del router Cisco RV en los dispositivos RV220W, anterior a 1.0.5.9 en los dispositivos RV120W, y anterior a 1.0.4.14 en los dispositivos RV180 y RV180W permite a usuarios remotos autenticados ejecutar comandos arbitrarios a través de una solicitud HTTP manipulada, también conocido como Bug ID CSCuh87126.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-02-25 CVE Reserved
- 2014-11-06 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2014/Nov/6 | Mailing List | |
http://www.securityfocus.com/archive/1/533917/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id/1031171 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98497 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rv | 2018-10-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Rv120w Firmware Search vendor "Cisco" for product "Rv120w Firmware" | <= 1.0.5.8 Search vendor "Cisco" for product "Rv120w Firmware" and version " <= 1.0.5.8" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv120w Search vendor "Cisco" for product "Rv120w" | - | - |
Affected
|
Cisco Search vendor "Cisco" | Rv220w Firmware Search vendor "Cisco" for product "Rv220w Firmware" | <= 1.0.5.8 Search vendor "Cisco" for product "Rv220w Firmware" and version " <= 1.0.5.8" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv220w Search vendor "Cisco" for product "Rv220w" | - | - |
Affected
|
Cisco Search vendor "Cisco" | Rv180 Firmware Search vendor "Cisco" for product "Rv180 Firmware" | <= 1.0.3.10 Search vendor "Cisco" for product "Rv180 Firmware" and version " <= 1.0.3.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv180 Search vendor "Cisco" for product "Rv180" | - | - |
Affected
|
Cisco Search vendor "Cisco" | Rv180 Firmware Search vendor "Cisco" for product "Rv180 Firmware" | <= 1.0.3.10 Search vendor "Cisco" for product "Rv180 Firmware" and version " <= 1.0.3.10" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv180w Search vendor "Cisco" for product "Rv180w" | - | - |
Affected
|