Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105792
Category:CISCO
Title:Cisco RV220W Management Authentication Bypass Vulnerability
Summary:A vulnerability in the web-based management interface of Cisco; RV220W Wireless Network Security Firewall devices could allow an unauthenticated, remote attacker; to bypass authentication and gain administrative privileges on a targeted device.
Description:Summary:
A vulnerability in the web-based management interface of Cisco
RV220W Wireless Network Security Firewall devices could allow an unauthenticated, remote attacker
to bypass authentication and gain administrative privileges on a targeted device.

Vulnerability Insight:
The vulnerability is due to insufficient input validation of
HTTP request headers that are sent to the web-based management interface of an affected device.
An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted HTTP
request that contains malicious SQL statements to the management interface of a targeted device.
Depending on whether remote management is configured for the device, the management interface may
use the SQL code in the HTTP request header to determine user privileges for the device.

Vulnerability Impact:
A successful exploit could allow the attacker to bypass
authentication on the management interface and gain administrative privileges on the device.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-6319
Cisco Security Advisory: 20160127 Cisco RV220W Management Authentication Bypass Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160127-rv220
http://www.securitytracker.com/id/1034830
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.