NVD

Id
85907  
Name
CVE-2017-3882  
Description
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642.  
Reject
 
CVSS Version
2  
CVSS Score
8.3  
Severity
High  
CVSS Base Score
8.3  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-07-18  
Published
2017-05-16  
Modified Date
2017-07-10  
Seq
2017-3882  

Actions