5
CVE-2011-1647
- EPSS 1.17%
- Veröffentlicht 31.05.2011 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:29:44
- Erkennungen
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the private key for the admin SSL certificate via unspecified vectors, aka Bug ID CSCtn23871.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Rvs4000 Software Version 1.3.0.5
Cisco ≫ Rvs4000 Software Version 1.3.1.0
Cisco ≫ Rvs4000 Software Version 1.3.2.0
Cisco ≫ Rvs4000 Software Version 2.0.0.3
Cisco ≫ Wrvs4400n Software Version 1.3.0.5
Cisco ≫ Wrvs4400n Software Version 1.3.1.0
Cisco ≫ Wrvs4400n Software Version 1.3.2.0
Cisco ≫ Wrvs4400n Software Version 2.0.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f190.shtml
http://www.securitytracker.com/id?1025565
http://www.securityfocus.com/bid/47985