CVE-2011-1646: Code Injection
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1646?
CVE-2011-1646 is classified as a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2011-1646?
To address CVE-2011-1646, you should upgrade your Cisco RVS4000 or WRVS4400N firmware to the latest version available.
Which affected versions are vulnerable to CVE-2011-1646?
CVE-2011-1646 affects Cisco RVS4000 firmware versions prior to 1.3.3.4 and 2.0.2.7, as well as WRVS4400N firmware versions prior to 2.0.2.1.
What types of attacks can leverage CVE-2011-1646?
CVE-2011-1646 could be exploited by remote authenticated users to execute arbitrary commands on the affected routers.
Is CVE-2011-1646 a permanent vulnerability?
CVE-2011-1646 is not permanent as it can be mitigated through timely firmware updates provided by Cisco.