5.3
CVE-2019-1899
- EPSS 3.38%
- Veröffentlicht 20.06.2019 03:15:12
- Zuletzt bearbeitet 21.11.2024 04:37:38
- Erkennungen
Cisco RV110W, RV130W, and RV215W Routers Information Disclosure Vulnerability
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Rv110w Firmware Version -
Cisco ≫ Rv130w Firmware Version -
Cisco ≫ Rv215w Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.38% | 0.872 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| Cisco PSIRT | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
https://www.tenable.com/security/research/tra-2019-29
http://www.securityfocus.com/bid/108867
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-rv-infodis