Number: AV19-254
Date: 7 November 2019
On 6 November 2019 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note, a vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers, tracked as CVE-2019-15271, could allow an authenticated, remote actor to execute arbitrary commands with root privileges by sending a malicious HTTP request to the targeted device.
This vulnerability affects the following Cisco Small Business RV Series Routers if they are running a firmware release earlier than 4.2.3.10:
• RV016 Multi-WAN VPN Router
• RV042 Dual WAN VPN Router
• RV042G Dual Gigabit WAN VPN Router
• RV082 Dual WAN VPN Router
The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:
https://tools.cisco.com/security/center/publicationListing.x
Note to Readers
The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada’s national authority on cyber security and we lead the government’s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.