← Back

CVE-2017-3882

nvd nist
Published: May 16, 2017Modified: May 13, 2026

JSON object

Loading...
9.6
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 6.0
Source: NVD

Description

A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642.

Affected (15)

2 products
Configuration A
15 vulnerable · 15 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 1.0.0.30
Version 1.0.1.19
Version 1.0.1.9
Version 1.0.2.6
Version 1.0.3.10
Version 1.0.39
Version 1.0.4.10
Version 1.0.4.14
Version 1.0.5.4
Version 1.0.5.4(gd)
Version 1.0.5.5
Version 1.0.5.6
Version 1.0.5.8
Version 1.0.6.6
Version 0.2
Running on/withPlatform Versions
Cisco
Rv042
All versions
Cisco
Rv042g
All versions
Cisco
Rv082
All versions
Cisco
Rv110w
All versions
Cisco
Rv130
All versions
Cisco
Rv130 Wf
All versions
Cisco
Rv130w
All versions
Cisco
Rv130w Wf
All versions
Cisco
Rv132w
All versions
Cisco
Rv134w
All versions
Cisco
Rv215w
All versions
Cisco
Rv320
All versions
Cisco
Rv320 Wf
All versions
Cisco
Rv325
All versions
Cisco
Rv325 Wf
All versions

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.