Vulnerabilities > Cisco > Wrvs4400N Software > 1.3.1.0

DATE CVE VULNERABILITY TITLE RISK
2011-05-31 CVE-2011-1647 Information Exposure vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the private key for the admin SSL certificate via unspecified vectors, aka Bug ID CSCtn23871.
network
low complexity
cisco CWE-200
5.0
2011-05-31 CVE-2011-1646 Code Injection vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.
network
low complexity
cisco CWE-94
critical
9.0
2011-05-31 CVE-2011-1645 Configuration vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the backup configuration file, and consequently execute arbitrary code, via unspecified vectors, aka Bug ID CSCtn23871.
network
cisco CWE-16
critical
9.3