Input validation error in Cisco Systems, Inc products - CVE-2019-15957

 

Input validation error in Cisco Systems, Inc products - CVE-2019-15957

Published: November 8, 2019


Vulnerability identifier: #VU22601
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15957
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary commands on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. A remote authenticated administrator can provide malicious input to a specific field in the web-based management interface of an affected device and execute arbitrary commands on the underlying Linux operating system.


Affected software

Small Business RV325 Dual Gigabit WAN VPN Router
Cisco RV082 Dual WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router
Cisco RV016 Multi-WAN VPN Router
Cisco RV042 Dual WAN VPN Router
Cisco RV042G Dual Gigabit WAN VPN Router

How to mitigate CVE-2019-15957

Install updates from vendor's website.

Small Business RV325 Dual Gigabit WAN VPN Router - update to 1.5.1.05
Cisco RV082 Dual WAN VPN Router - update to 4.2.3.10
Small Business RV320 Dual Gigabit WAN VPN Router - update to 1.5.1.05
Cisco RV016 Multi-WAN VPN Router - update to 4.2.3.10
Cisco RV042 Dual WAN VPN Router - update to 4.2.3.10
Cisco RV042G Dual Gigabit WAN VPN Router - update to 4.2.3.10

External References

Related Security Bulletins