SB2017050505 - Security bypass in Cisco CVR100W Wireless-N VPN Router
Published: May 5, 2017
Security Bulletin ID
SB2017050505
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security bypass (CVE-ID: CVE-2017-6620)
The vulnerability allows a remote unauthenticated attacker to bypass the remote management ACL.The weakness exists due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. A remote attacker can connect to the management IP address or domain name of the targeted device and if the Remote Management configuration parameter is Disabled, bypass the configured remote management ACL.
Successful exploitation of the vulnerability results in security bypass.
Remediation
Install update from vendor's website.