cisco-sa-20190404-rv-weak-encrypt: Cisco Small Business RV320 and RV325 Routers Weak Credential Encryption Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices use weak encryption algorithms for user credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack and decrypting intercepted credentials. A successful exploit could allow the attacker to gain access to an affected device with administrator privileges. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190404-rv-weak-encrypt
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190404-rv-weak-encrypt?
The severity of cisco-sa-20190404-rv-weak-encrypt is considered high due to the potential unauthorized access to administrative credentials.
How do I fix cisco-sa-20190404-rv-weak-encrypt?
To fix cisco-sa-20190404-rv-weak-encrypt, update the affected Cisco RV320 and RV325 routers to the latest firmware version provided by Cisco.
What devices are affected by cisco-sa-20190404-rv-weak-encrypt?
The devices affected by cisco-sa-20190404-rv-weak-encrypt are the Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers.
Can an attacker exploit cisco-sa-20190404-rv-weak-encrypt remotely?
Yes, an attacker can exploit cisco-sa-20190404-rv-weak-encrypt remotely without authentication.
What type of attack is possible due to cisco-sa-20190404-rv-weak-encrypt?
An attacker could perform credential access attacks due to weak encryption in the web-based management interface of the affected routers.