Input validation error in Cisco Systems, Inc products - CVE-2019-15957

 

Input validation error in Cisco Systems, Inc products - CVE-2019-15957

Published: November 8, 2019


Vulnerability identifier: #VU22601
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-15957
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco RV016 Multi-WAN VPN Router
Cisco RV042 Dual WAN VPN Router
Cisco RV042G Dual Gigabit WAN VPN Router
Cisco RV082 Dual WAN VPN Router
Small Business RV320 Dual Gigabit WAN VPN Router
Small Business RV325 Dual Gigabit WAN VPN Router

Detailed vulnerability description

The vulnerability allows a remote attacker to inject arbitrary commands on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. A remote authenticated administrator can provide malicious input to a specific field in the web-based management interface of an affected device and execute arbitrary commands on the underlying Linux operating system.


How to mitigate CVE-2019-15957

Install updates from vendor's website.

Sources