9

CVE-2011-1646

The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.

Data is provided by the National Vulnerability Database (NVD)
CiscoRvs4000 Version1
CiscoRvs4000 Version2
CiscoRvs4000 Software Version1.3.0.5
CiscoRvs4000 Software Version1.3.1.0
CiscoRvs4000 Software Version1.3.2.0
CiscoRvs4000 Software Version2.0.0.3
CiscoWrvs4400n Version1.0
CiscoWrvs4400n Version1.1
CiscoWrvs4400n Version2
CiscoWrvs4400n Software Version1.3.0.5
CiscoWrvs4400n Software Version1.3.1.0
CiscoWrvs4400n Software Version1.3.2.0
CiscoWrvs4400n Software Version2.0.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.62% 0.691
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.