CVE ID | CVE-2021-1415 |
CVSS SCORE | 5.5, AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
AFFECTED VENDORS |
Cisco |
AFFECTED PRODUCTS |
RV340 |
VULNERABILITY DETAILS |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Cisco RV340 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of JSON-RPC requests. When parsing the usmUserEngineID property, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user. |
ADDITIONAL DETAILS |
Cisco has issued an update to correct this vulnerability. More details can be found at:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b |
DISCLOSURE TIMELINE |
|
CREDIT | T Shiomitsu |