CVE-2012-0363

The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:cisco:small_business_srp520_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.01:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.09:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.11:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.19:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.23:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp521w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp526w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp527w:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:cisco:small_business_srp520-u_series_firmware:1.1.0:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp521w-u:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp526w-u:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp527w-u:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:cisco:small_business_srp540_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp540_series_firmware:1.02.00.023:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp541w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp546w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp547w:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500 - Patch, Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500 - Patch, Vendor Advisory
References () http://www.securitytracker.com/id?1026736 - () http://www.securitytracker.com/id?1026736 -

Information

Published : 2012-02-25 04:21

Updated : 2024-11-21 01:34


NVD link : CVE-2012-0363

Mitre link : CVE-2012-0363

CVE.ORG link : CVE-2012-0363


JSON object : View

Products Affected

cisco

  • small_business_srp526w-u
  • small_business_srp521w-u
  • small_business_srp527w-u
  • small_business_srp520_series_firmware
  • small_business_srp547w
  • small_business_srp520-u_series_firmware
  • small_business_srp527w
  • small_business_srp540_series_firmware
  • small_business_srp541w
  • small_business_srp521w
  • small_business_srp526w
  • small_business_srp546w
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')