VulnerabilityModified
CVE-2014-2179
The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.
MEDIUM 5.0EPSS 1.63%
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/rv180 firmware · cisco/rv180 · cisco/rv180w · cisco/rv120w firmware · cisco/rv120w · cisco/rv220w firmware · cisco/rv220w
- Source
- psirt@cisco.com
References
- http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/Nov/6
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rvPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/533917/100/0/threaded
- http://www.securitytracker.com/id/1031171
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98499
- http://packetstormsecurity.com/files/128992/Cisco-RV-Overwrite-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/Nov/6
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141105-rvPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/533917/100/0/threaded
- http://www.securitytracker.com/id/1031171
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98499
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.