CVE-2012-0363

The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:cisco:small_business_srp520_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.01:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.09:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.11:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.19:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp520_series_firmware:1.01.23:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp521w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp526w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp527w:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:cisco:small_business_srp520-u_series_firmware:1.1.0:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp521w-u:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp526w-u:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp527w-u:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:a:cisco:small_business_srp540_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:small_business_srp540_series_firmware:1.02.00.023:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:small_business_srp541w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp546w:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:small_business_srp547w:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-02-25 04:21

Updated : 2024-02-04 17:54


NVD link : CVE-2012-0363

Mitre link : CVE-2012-0363

CVE.ORG link : CVE-2012-0363


JSON object : View

Products Affected

cisco

  • small_business_srp527w-u
  • small_business_srp526w
  • small_business_srp546w
  • small_business_srp527w
  • small_business_srp521w-u
  • small_business_srp520_series_firmware
  • small_business_srp541w
  • small_business_srp547w
  • small_business_srp526w-u
  • small_business_srp520-u_series_firmware
  • small_business_srp540_series_firmware
  • small_business_srp521w
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')