SB2017050505 - Security bypass in Cisco CVR100W Wireless-N VPN Router



SB2017050505 - Security bypass in Cisco CVR100W Wireless-N VPN Router

Published: May 5, 2017

Security Bulletin ID SB2017050505
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security bypass (CVE-ID: CVE-2017-6620)

The vulnerability allows a remote unauthenticated attacker to bypass the remote management ACL.

The weakness exists due to incorrect implementation of the ACL decision made during the ingress connection request to the remote management interface. A remote attacker can connect to the management IP address or domain name of the targeted device and if the Remote Management configuration parameter is Disabled, bypass the configured remote management ACL.

Successful exploitation of the vulnerability results in security bypass.

Remediation

Install update from vendor's website.