CVE-2014-2178
Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack…
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack the authentication of administrators, aka Bug ID CSCuh87145.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- cisco/rv180 firmware · cisco/rv180 · cisco/rv180w · cisco/rv220w firmware · cisco/rv220w · cisco/rv120w firmware · cisco/rv120w
- Source
- psirt@cisco.com
References
- http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/Nov/6
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rvPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/533917/100/0/threaded
- http://www.securitytracker.com/id/1031171
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98498
- http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/Nov/6
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rvPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/533917/100/0/threaded
- http://www.securitytracker.com/id/1031171
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98498
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.