Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4005

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2011-4005
Last Modified 26 Jan 2012 11:03:22
Published 03 Nov 2011 06:55:08
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4005

Summary

Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546W, and SRP547W with firmware before 1.2.1 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands, aka Bug ID CSCtr45124.

Vulnerable Systems

Application

  • Cisco Small Business Srp520 Series Firmware 1.00.06

  • Cisco Small Business Srp520 Series Firmware 1.01.01

  • Cisco Small Business Srp520 Series Firmware 1.01.19 Mr3

  • Cisco Small Business Srp520 Series Firmware 1.01.23

  • Cisco Small Business Srp540 Series Firmware 1.02.00

  • Cisco Small Business Srp540 Series Firmware 1.02.01 Mr2


References

CISCO - 20111102 Cisco Small Business SRP500 Series Command Injection Vulnerability

XF - cisco-small-business-command-exec(71103)

SECTRACK - 1026266

BID - 50495

SECUNIA - 46664


Last Updated: 27 May 2016 10:58:06