CVE-2014-2179: Input Validation
Published Nov 7, 2014
·Updated
The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.
Affected Software
7 affected components
Cisco Rv180 Firmware<=1.0.3.10
Cisco RV180
Cisco RV180W
Cisco Rv120w Firmware<=1.0.5.8
Cisco RV120W
Cisco Rv220w Firmware<=1.0.5.8
Cisco RV220W
Remediation
Event History
Nov 7, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2179?
CVE-2014-2179 has a medium severity rating due to its potential for remote exploitation.
2
How do I fix CVE-2014-2179?
To fix CVE-2014-2179, update the firmware on affected Cisco RV devices to the latest version that is not vulnerable.
3
Which devices are affected by CVE-2014-2179?
CVE-2014-2179 affects Cisco RV220W, RV120W, RV180, and RV180W routers with specific firmware versions.
4
What type of attack does CVE-2014-2179 allow?
CVE-2014-2179 allows remote attackers to upload files to arbitrary locations on the vulnerable devices.
5
When was CVE-2014-2179 disclosed?
CVE-2014-2179 was disclosed on November 5, 2014.