Umbra Wiki cve cve/CVE-2019-1652
Back to wiki

CVE-2019-1652 — Cisco Small Business Routers Improper Input Validation Vulnerability

provenance: imported · CVE: CVE-2019-1652 · CWE: CWE-20

CVE-2019-1652: Cisco Small Business Routers Improper Input Validation Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Cisco
Product Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
Date added 2022-03-03
Due date 2022-03-17
Ransomware campaign use Unknown

Description

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-1652

Weakness behind it

CISA records this vulnerability as an instance of CWE-20. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-1652
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →