SB2017050506 - Arbitrary code execution in Cisco CVR100W Wireless-N VPN Router
Published: May 5, 2017 Updated: May 5, 2017
Security Bulletin ID
SB2017050506
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2017-3882)
The vulnerability allows an unauthenticated, Layer 2–adjacent attacker to cause DoS condition or execute arbitrary code on the target system.The weakness exists due to buffer overflow caused by incomplete range checks of the UPnP input data. An attacker can send a malicious request to the UPnP listening port, trigger memory corruption, cause the device to reload or potentially execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in denial of service or arbitrary code execution.
Remediation
Install update from vendor's website.