Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0683


The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to intercept requests, aka Bug IDs CSCul94527, CSCum86264, and CSCum86275.


Published

2014-03-06T11:55:05.287

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco rv110w_firmware ≤ 1.2.0.9 Yes
Hardware cisco rv110w - Yes
Operating System cisco rv215w_firmware ≤ 1.1.0.5 Yes
Hardware cisco rv215w - Yes
Operating System cisco cvr100w_firmware ≤ 1.0.1.19 Yes
Hardware cisco cvr100w - Yes

References