CVE-2012-0363: Code Injection
The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0363?
CVE-2012-0363 is classified as a high-severity command injection vulnerability.
How do I fix CVE-2012-0363?
To remediate CVE-2012-0363, upgrade the firmware of affected Cisco SRP devices to at least version 1.1.26 or 1.2.4.
Which devices are affected by CVE-2012-0363?
CVE-2012-0363 affects Cisco SRP 520 and 540 series devices with specific firmware versions prior to the fixed releases.
What type of attack is possible with CVE-2012-0363?
CVE-2012-0363 allows remote authenticated users to execute arbitrary commands on the affected Cisco devices.
Is CVE-2012-0363 being actively exploited?
There is no public information indicating active exploitation of CVE-2012-0363, but it remains a significant security risk.