Skip to content
COOEY

EXPOSURES › CVE-2019-1652

CVE-2019-1652

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1652 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Cisco Small Business RV320/RV325 routers had an improper input validation flaw allowing authenticated remote attackers to execute arbitrary commands.

The web-based management interface of Cisco Small Business RV320 and RV325 routers suffered from improper input validation, enabling authenticated remote attackers with administrative privileges to execute arbitrary commands. DIB organizations must care because this RCE flaw, listed in CISA's KEV catalog, indicates a known, actively exploited vulnerability that could compromise network integrity and violate CMMC/NIST 800-171 controls if unpatched. Organizations should immediately verify patch levels on all legacy Cisco Small Business routers and replace them with hardened alternatives.

Shame score — A known, actively exploited RCE vulnerability in widely deployed small business routers demonstrates negligent security development and prolonged exposure to active exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized