ZeroHour
Security Affairspublished ()ingested @securityaffairs

Cisco fixes 5 critical flaws that could allow router firewall takeover

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3140
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthoriz

A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit this vulnerability by submitting a malicious request to an affected system. An exploit could allow the attacker to gain administrative-level privileges on the system. The attacker needs a valid username to exploit this vulnerability.

NVD description · AI analysis pending
9.83%
  • cisco prime license manager
CVE-2020-3144
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router,

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary commands with administrative commands on an affected device. The vulnerability is due to improper session management on affected devices. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.

NVD description · AI analysis pending
9.83%
  • cisco rv110w firmware
  • cisco rv130 firmware
  • cisco rv130w firmware
  • +1 more
CVE-2020-3331
+2 in the same advisory: …3323 …3330
A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthentica

A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input data by the web-based management interface. An attacker could exploit this vulnerability by sending crafted requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user.

NVD description · AI analysis pending
9.842%
  • cisco rv110w wireless-n vpn firewall firmware
  • cisco rv215w wireless-n vpn router firmware
Full article268 words · extracted from securityaffairs.com · click to collapse

Cisco addresses a critical remote code execution (RCE), authentication bypass, and static default credential flaws that could lead to full router takeover.

Cisco has released security updates to address critical remote code execution (RCE), authentication bypass, and static default credential vulnerabilities affecting multiple router and firewall devices. An attacker could exploit the vulnerabilities to completely takeover the network devices.

Cisco also addressed a privilege escalation issue that impacts the Cisco Prime License Manager software.

The five vulnerabilities have been labeled as critical and rated 9.8 out of 10 CVSS base score, below the list of the issues fixed by Cisco.

VulnerabilityCVE-ID
Cisco Small Business RV110W Wireless-N VPN Firewall Static Default Credential VulnerabilityCVE-2020-3330
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution VulnerabilityCVE-2020-3323
Cisco RV110W, RV130, RV130W, and RV215W Routers Authentication Bypass VulnerabilityCVE-2020-3144
Cisco RV110W and RV215W Series Routers Arbitrary Code Execution VulnerabilityCVE-2020-3331
Cisco Prime License Manager Privilege Escalation VulnerabilityCVE-2020-3140

The Cisco Product Security Incident Response Team (PSIRT) confirmed that it is not aware of any public announcements or malicious use of the above vulnerabilities.

The tech giant confirmed that there are no workarounds that fix these vulnerabilities.

The company acknowledged the external security researchers Larryxi of XDSEC, Gyengtak Kim, Jeongun Baek, and Sanghyuk Lee of GeekPwn, Quentin Kaiser, and Adam Engle of AdventHealth for the flaws.

Cisco released security updates to address other 22 high and medium severity security vulnerabilities impacting several routers, WebEx, Cisco SD-WAN Solution Software versions and other software.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Cisco)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/105953/security/cisco-router-firewall-flaws.html