Cisco SRP 500 Series Unauthenticated Configuration Upload Vulnerability
9 Mar. 2012
Summary
Cisco SRP 500 Series devices contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to upload an unauthorized configuration file..
Vulnerable Systems:
* Cisco SRP 520 Series firmware prior to version 1.1.26
* Cisco SRP 520W-U Series firmware prior to version 1.2.4
* Cisco SRP 540 Series firmware prior to version 1.2.4
Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.
Vendor Status:
Cisco has released free software updates that address this vulnerability.