Vulnerability CVE-2011-4500


Published: 2011-11-22   Modified: 2012-02-13

Description:
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.

Type:

CWE-16

(Configuration)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Linksys -> Wrt54gx 
Cisco -> Linksys wrt54gx router firmware 

 References:
http://www.kb.cert.org/vuls/id/357851
http://www.upnp-hacks.org/devices.html

Copyright 2024, cxsecurity.com

 

Back to Top