ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Will Not Patch Critical RCE Flaw Affecting End-of

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1479
+2 in the same advisory: …1480 …1137
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, l

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

NVD description · AI analysis pending
9.8
group max
2%
  • cisco catalyst sd-wan manager
  • cisco sd-wan vmanage
CVE-2021-1459
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote a

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device. Cisco has not released software updates that address this vulnerability.

NVD description · AI analysis pending
9.83%
  • cisco rv110w firmware
  • cisco rv130 firmware
  • cisco rv130w firmware
  • +1 more
Full article324 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 09, 2021

Networking equipment major Cisco Systems has said it does not plan to fix a critical security vulnerability affecting some of its Small Business routers, instead urging users to replace the devices.

The bug, tracked as CVE-2021-1459, is rated with a CVSS score of 9.8 out of 10, and affects RV110W VPN firewall and Small Business RV130, RV130W, and RV215W routers, allowing an unauthenticated, remote attacker to execute arbitrary code on an affected appliance.

The flaw, which stems from improper validation of user-supplied input in the web-based management interface, could be exploited by a malicious actor to send specially-crafted HTTP requests to the targeted device and achieve remote code execution.

"A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device," Cisco said in its advisory.

Security researcher Treck Zhou has been credited with reporting the vulnerability. Although the company noted there's been no evidence of active exploitation attempts in the wild, it doesn't intend to release a patch or make any workarounds available, citing that the products have reached end-of-life.

"The Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers have entered the end-of-life process," the firm said. "Customers are encouraged to migrate to the Cisco Small Business RV132W, RV160, or RV160W Routers."

Separately, Cisco has also released software updates to address multiple vulnerabilities in Cisco SD-WAN vManage Software (CVE-2021-1137, CVE-2021-1479, and CVE-2021-1480) that could permit an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system.

A consequence of a buffer overflow condition, CVE-2021-1479 is rated 9.8 in severity, and a successful exploitation of which "could allow the attacker to execute arbitrary code on the underlying operating system with root privileges."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/cisco-will-not-patch-critical-rce-flaw.html