CVE-2019-15271 — Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
CVE-2019-15271: Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Cisco |
| Product | RV Series Routers |
| Date added | 2022-06-08 |
| Due date | 2022-06-22 |
| Ransomware campaign use | Unknown |
Description
A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2019-15271
Weakness behind it
CISA records this vulnerability as an instance of CWE-502. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-15271
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
See all 1,745 pages under Vulnerabilities (CVE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.