Cisco SRP 500 Series Web Interface Command Injection Vulnerability
9 Mar. 2012
Summary
Cisco SRP 500 Series devices contain a command injection vulnerability that could allow an authenticated session to inject commands to be executed by the operating system.
Credit:
The information has been provided by Michal Sajdak of Securitum.
Vulnerable Systems:
* Cisco SRP 520 Series firmware prior to version 1.1.26
* Cisco SRP 520W-U Series firmware prior to version 1.2.4
* Cisco SRP 540 Series firmware prior to version 1.2.4
The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.
Vendor Status:
Cisco has released free software updates that address this vulnerability.