VDB
CVE-2019-1898
CVE-2019-1898
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file.
EPSS 78.68% · 99.1th percentile
Risk Scores
CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
78.68%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco RV130W Wireless-N Multifunction VPN Router Firmware | unspecified |
| cisco | rv215w_firmware | |
| cisco | rv130w_firmware | |
| cisco | rv110w_firmware |
Exploit Intelligence
- https://www.tenable.com/security/research/tra-2019-29 (nist-nvd)
- 20190619 Cisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access Vulnerability (circl)
- 108865 (circl)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- web_poc_map_v2.yaml (github-poc)
- Nuclei Template: CVE-2019-1898 (nuclei-template)
- Nuclei Template: CVE-2019-1898 (nuclei-template)
…and 4 more exploits
Timeline
- Jun 19, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 11, 2023 EPSS Score
- Jul 14, 2023 EPSS Score
- Aug 29, 2023 EPSS Score