CVE-2021-1472
08.04.2021, 04:15
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | rv160_firmware | 𝑥 < 1.0.01.03 |
cisco | rv160w_firmware | 𝑥 < 1.0.01.03 |
cisco | rv260_firmware | 𝑥 < 1.0.01.03 |
cisco | rv260p_firmware | 𝑥 < 1.0.01.03 |
cisco | rv260w_firmware | 𝑥 < 1.0.01.03 |
cisco | rv340_firmware | 𝑥 < 1.0.03.21 |
cisco | rv340w_firmware | 𝑥 < 1.0.03.21 |
cisco | rv345_firmware | 𝑥 < 1.0.03.21 |
cisco | rv345p_firmware | 𝑥 < 1.0.03.21 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References