Podatność w interfejsie webowym routerów Cisco RV132W i RV134W umożliwia nieuwierzytelnionemu atakującemu zdalny odczyt parametrów konfiguracyjnych urządzenia, w tym hasła administratora. Brak mechanizmu uwierzytelnienia na wybranych podstronach interfejsu czyni tę lukę szczególnie niebezpieczną.
▸ Pokaż oryginał (EN)
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.
Wybrane strony interfejsu webowego urządzeń nie wymagają uwierzytelnienia użytkownika, mimo że zawierają poufne informacje konfiguracyjne. Atakujący wysyła spreparowane żądanie HTTP do podatnego urządzenia, a następnie analizuje treść odpowiedzi HTTP. W odpowiedzi mogą znajdować się krytyczne dane, takie jak hasło administratora.
Atakujący może uzyskać pełny dostęp do parametrów konfiguracyjnych urządzenia, w tym hasła administratora, co w praktyce umożliwia przejęcie kontroli nad routerem i infrastrukturą VPN.
Należy zastosować patche dostępne u producenta zgodnie z referencjami — szczegóły w Cisco Security Advisory cisco-sa-20180207-rv13x_2 dostępnym pod adresem https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-rv13x_2
Cisco RV132W ADSL2+ Wireless-N VPN Router oraz Cisco RV134W VDSL2 Wireless-AC VPN Router — wersje firmware wskazane w referencjach producenta (Cisco Bug IDs: CSCvg92739, CSCvh60172)
Podatność opublikowana przez Cisco 7–8 lutego 2018 r. Dotyczy dwóch różnych modeli routerów z odrębnymi identyfikatorami błędów: CSCvg92739 (RV132W) oraz CSCvh60172 (RV134W).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco Rv132w
HWCiscowszystkie wersjeCisco Rv132w Firmware
OSCisco1.0.0.11.0.1.8Cisco Rv134w
HWCiscowszystkie wersjeCisco Rv134w Firmware
OSCisco1.0.0.11.0.1.8
Powiązane podatności
RCE i DoS w interfejsie web routerów Cisco RV132W i RV134W VPN
RCE z uprawnieniami root w Cisco CVR100W via UPnP — buffer overflow
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Busi...
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Busi...
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Busi...