7.2
CVE-2023-20250
- EPSS 0.24%
- Published 06.09.2023 17:15:50
- Last modified 21.11.2024 07:40:59
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of requests that are sent to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code with root privileges on an affected device. To exploit this vulnerability, the attacker must have valid Administrator credentials on the affected device.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Rv110w Firmware Version1.0.0.2
Cisco ≫ Rv110w Firmware Version1.0.0.21
Cisco ≫ Rv110w Firmware Version1.0.0.30
Cisco ≫ Rv110w Firmware Version1.0.1.1
Cisco ≫ Rv110w Firmware Version1.0.1.3
Cisco ≫ Rv110w Firmware Version1.0.1.6
Cisco ≫ Rv110w Firmware Version1.0.1.99
Cisco ≫ Rv110w Firmware Version1.0.2.7
Cisco ≫ Rv110w Firmware Version1.0.2.99
Cisco ≫ Rv110w Firmware Version1.0.3.14
Cisco ≫ Rv110w Firmware Version1.0.3.16
Cisco ≫ Rv110w Firmware Version1.0.3.22
Cisco ≫ Rv110w Firmware Version1.0.3.28
Cisco ≫ Rv110w Firmware Version1.0.3.44
Cisco ≫ Rv110w Firmware Version1.0.3.45
Cisco ≫ Rv110w Firmware Version1.0.3.51
Cisco ≫ Rv110w Firmware Version1.0.3.52
Cisco ≫ Rv110w Firmware Version1.0.3.54
Cisco ≫ Rv110w Firmware Version1.0.3.55
Cisco ≫ Rv110w Firmware Version1.1.0.5
Cisco ≫ Rv110w Firmware Version1.1.0.6
Cisco ≫ Rv110w Firmware Version1.1.0.9
Cisco ≫ Rv110w Firmware Version1.2.0.8
Cisco ≫ Rv110w Firmware Version1.2.0.9
Cisco ≫ Rv110w Firmware Version1.2.0.10
Cisco ≫ Rv110w Firmware Version1.2.0.14
Cisco ≫ Rv110w Firmware Version1.2.0.15
Cisco ≫ Rv110w Firmware Version1.2.0.99
Cisco ≫ Rv110w Firmware Version1.2.1.4
Cisco ≫ Rv110w Firmware Version1.2.1.7
Cisco ≫ Rv110w Firmware Version1.2.2.1
Cisco ≫ Rv110w Firmware Version1.2.2.4
Cisco ≫ Rv110w Firmware Version1.2.2.5
Cisco ≫ Rv110w Firmware Version1.2.2.8
Cisco ≫ Rv110w Firmware Version1.3.0.4
Cisco ≫ Rv110w Firmware Version1.3.0.7
Cisco ≫ Rv110w Firmware Version1.3.0.8
Cisco ≫ Rv110w Firmware Version1.3.0.99
Cisco ≫ Rv110w Firmware Version1.3.1.1
Cisco ≫ Rv110w Firmware Version1.3.1.4
Cisco ≫ Rv110w Firmware Version1.3.1.5
Cisco ≫ Rv110w Firmware Version1.3.1.7
Cisco ≫ Rv130 Firmware Version1.0.0.2
Cisco ≫ Rv130 Firmware Version1.0.0.21
Cisco ≫ Rv130 Firmware Version1.0.0.30
Cisco ≫ Rv130 Firmware Version1.0.1.1
Cisco ≫ Rv130 Firmware Version1.0.1.3
Cisco ≫ Rv130 Firmware Version1.0.1.6
Cisco ≫ Rv130 Firmware Version1.0.1.99
Cisco ≫ Rv130 Firmware Version1.0.2.7
Cisco ≫ Rv130 Firmware Version1.0.2.99
Cisco ≫ Rv130 Firmware Version1.0.3.14
Cisco ≫ Rv130 Firmware Version1.0.3.16
Cisco ≫ Rv130 Firmware Version1.0.3.22
Cisco ≫ Rv130 Firmware Version1.0.3.28
Cisco ≫ Rv130 Firmware Version1.0.3.44
Cisco ≫ Rv130 Firmware Version1.0.3.45
Cisco ≫ Rv130 Firmware Version1.0.3.51
Cisco ≫ Rv130 Firmware Version1.0.3.52
Cisco ≫ Rv130 Firmware Version1.0.3.54
Cisco ≫ Rv130 Firmware Version1.0.3.55
Cisco ≫ Rv130 Firmware Version1.1.0.5
Cisco ≫ Rv130 Firmware Version1.1.0.6
Cisco ≫ Rv130 Firmware Version1.1.0.9
Cisco ≫ Rv130 Firmware Version1.2.0.8
Cisco ≫ Rv130 Firmware Version1.2.0.9
Cisco ≫ Rv130 Firmware Version1.2.0.10
Cisco ≫ Rv130 Firmware Version1.2.0.14
Cisco ≫ Rv130 Firmware Version1.2.0.15
Cisco ≫ Rv130 Firmware Version1.2.0.99
Cisco ≫ Rv130 Firmware Version1.2.1.4
Cisco ≫ Rv130 Firmware Version1.2.1.7
Cisco ≫ Rv130 Firmware Version1.2.2.1
Cisco ≫ Rv130 Firmware Version1.2.2.4
Cisco ≫ Rv130 Firmware Version1.2.2.5
Cisco ≫ Rv130 Firmware Version1.2.2.8
Cisco ≫ Rv130 Firmware Version1.3.0.4
Cisco ≫ Rv130 Firmware Version1.3.0.7
Cisco ≫ Rv130 Firmware Version1.3.0.8
Cisco ≫ Rv130 Firmware Version1.3.0.99
Cisco ≫ Rv130 Firmware Version1.3.1.1
Cisco ≫ Rv130 Firmware Version1.3.1.4
Cisco ≫ Rv130 Firmware Version1.3.1.5
Cisco ≫ Rv130 Firmware Version1.3.1.7
Cisco ≫ Rv130w Firmware Version1.0.0.2
Cisco ≫ Rv130w Firmware Version1.0.0.21
Cisco ≫ Rv130w Firmware Version1.0.0.30
Cisco ≫ Rv130w Firmware Version1.0.1.1
Cisco ≫ Rv130w Firmware Version1.0.1.3
Cisco ≫ Rv130w Firmware Version1.0.1.6
Cisco ≫ Rv130w Firmware Version1.0.1.99
Cisco ≫ Rv130w Firmware Version1.0.2.7
Cisco ≫ Rv130w Firmware Version1.0.2.99
Cisco ≫ Rv130w Firmware Version1.0.3.14
Cisco ≫ Rv130w Firmware Version1.0.3.16
Cisco ≫ Rv130w Firmware Version1.0.3.22
Cisco ≫ Rv130w Firmware Version1.0.3.28
Cisco ≫ Rv130w Firmware Version1.0.3.44
Cisco ≫ Rv130w Firmware Version1.0.3.45
Cisco ≫ Rv130w Firmware Version1.0.3.51
Cisco ≫ Rv130w Firmware Version1.0.3.52
Cisco ≫ Rv130w Firmware Version1.0.3.54
Cisco ≫ Rv130w Firmware Version1.0.3.55
Cisco ≫ Rv130w Firmware Version1.1.0.5
Cisco ≫ Rv130w Firmware Version1.1.0.6
Cisco ≫ Rv130w Firmware Version1.1.0.9
Cisco ≫ Rv130w Firmware Version1.2.0.8
Cisco ≫ Rv130w Firmware Version1.2.0.9
Cisco ≫ Rv130w Firmware Version1.2.0.10
Cisco ≫ Rv130w Firmware Version1.2.0.14
Cisco ≫ Rv130w Firmware Version1.2.0.15
Cisco ≫ Rv130w Firmware Version1.2.0.99
Cisco ≫ Rv130w Firmware Version1.2.1.4
Cisco ≫ Rv130w Firmware Version1.2.1.7
Cisco ≫ Rv130w Firmware Version1.2.2.1
Cisco ≫ Rv130w Firmware Version1.2.2.4
Cisco ≫ Rv130w Firmware Version1.2.2.5
Cisco ≫ Rv130w Firmware Version1.2.2.8
Cisco ≫ Rv130w Firmware Version1.3.0.4
Cisco ≫ Rv130w Firmware Version1.3.0.7
Cisco ≫ Rv130w Firmware Version1.3.0.8
Cisco ≫ Rv130w Firmware Version1.3.0.99
Cisco ≫ Rv130w Firmware Version1.3.1.1
Cisco ≫ Rv130w Firmware Version1.3.1.4
Cisco ≫ Rv130w Firmware Version1.3.1.5
Cisco ≫ Rv130w Firmware Version1.3.1.7
Cisco ≫ Rv215w Firmware Version1.0.0.2
Cisco ≫ Rv215w Firmware Version1.0.0.21
Cisco ≫ Rv215w Firmware Version1.0.0.30
Cisco ≫ Rv215w Firmware Version1.0.1.1
Cisco ≫ Rv215w Firmware Version1.0.1.3
Cisco ≫ Rv215w Firmware Version1.0.1.6
Cisco ≫ Rv215w Firmware Version1.0.1.99
Cisco ≫ Rv215w Firmware Version1.0.2.7
Cisco ≫ Rv215w Firmware Version1.0.2.99
Cisco ≫ Rv215w Firmware Version1.0.3.14
Cisco ≫ Rv215w Firmware Version1.0.3.16
Cisco ≫ Rv215w Firmware Version1.0.3.22
Cisco ≫ Rv215w Firmware Version1.0.3.28
Cisco ≫ Rv215w Firmware Version1.0.3.44
Cisco ≫ Rv215w Firmware Version1.0.3.45
Cisco ≫ Rv215w Firmware Version1.0.3.51
Cisco ≫ Rv215w Firmware Version1.0.3.52
Cisco ≫ Rv215w Firmware Version1.0.3.54
Cisco ≫ Rv215w Firmware Version1.0.3.55
Cisco ≫ Rv215w Firmware Version1.1.0.5
Cisco ≫ Rv215w Firmware Version1.1.0.6
Cisco ≫ Rv215w Firmware Version1.1.0.9
Cisco ≫ Rv215w Firmware Version1.2.0.8
Cisco ≫ Rv215w Firmware Version1.2.0.9
Cisco ≫ Rv215w Firmware Version1.2.0.10
Cisco ≫ Rv215w Firmware Version1.2.0.14
Cisco ≫ Rv215w Firmware Version1.2.0.15
Cisco ≫ Rv215w Firmware Version1.2.0.99
Cisco ≫ Rv215w Firmware Version1.2.1.4
Cisco ≫ Rv215w Firmware Version1.2.1.7
Cisco ≫ Rv215w Firmware Version1.2.2.1
Cisco ≫ Rv215w Firmware Version1.2.2.4
Cisco ≫ Rv215w Firmware Version1.2.2.5
Cisco ≫ Rv215w Firmware Version1.2.2.8
Cisco ≫ Rv215w Firmware Version1.3.0.4
Cisco ≫ Rv215w Firmware Version1.3.0.7
Cisco ≫ Rv215w Firmware Version1.3.0.8
Cisco ≫ Rv215w Firmware Version1.3.0.99
Cisco ≫ Rv215w Firmware Version1.3.1.1
Cisco ≫ Rv215w Firmware Version1.3.1.4
Cisco ≫ Rv215w Firmware Version1.3.1.5
Cisco ≫ Rv215w Firmware Version1.3.1.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.448 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
psirt@cisco.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.