9
CVE-2011-1646
- EPSS 0.62%
- Veröffentlicht 31.05.2011 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Rvs4000 Software Version1.3.0.5
Cisco ≫ Rvs4000 Software Version1.3.1.0
Cisco ≫ Rvs4000 Software Version1.3.2.0
Cisco ≫ Rvs4000 Software Version2.0.0.3
Cisco ≫ Wrvs4400n Software Version1.3.0.5
Cisco ≫ Wrvs4400n Software Version1.3.1.0
Cisco ≫ Wrvs4400n Software Version1.3.2.0
Cisco ≫ Wrvs4400n Software Version2.0.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.62% | 0.691 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.