Cisco Small Business Routers RV016, RV042, RV042G, and RV082 Information Disclosure (cisco-sa-20191120-sbr-rv-infodis)

medium Nessus Plugin ID 131403

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco Small Business RV Series Router Firmware is affected by an information disclosure vulnerability in the web-based management interface due to improper authorization of HTTP requests. An unauthenticated, remote attacker can exploit this, by sending crafted HTTP requests to the web-based management interface, in order to view information displayed in the web-based management interface without authentication.

Please see the included Cisco BID(s) and Cisco Security Advisory for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvq76840

See Also

http://www.nessus.org/u?3b86d905

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq76840

Plugin Details

Severity: Medium

ID: 131403

File Name: cisco-sa-20191120-sbr-rv-infodis.nasl

Version: 1.12

Type: local

Family: CISCO

Published: 12/2/2019

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2019-15990

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/o:cisco:small_business_rv_series_router_firmware

Required KB Items: Cisco/Small_Business_Router/Version, Cisco/Small_Business_Router/Model

Exploit Ease: No known exploits are available

Patch Publication Date: 11/20/2019

Vulnerability Publication Date: 11/20/2019

Reference Information

CVE: CVE-2019-15990

CWE: 285

CISCO-SA: cisco-sa-20191120-sbr-rv-infodis

IAVA: 2019-A-0429-S

CISCO-BUG-ID: CSCvq76840