CVE-2019-15990
MEDIUMCisco Small Business RV Series Routers - Info Disclosure
Title source: llmDescription
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to view information displayed in the web-based management interface without authentication.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191120-sbr-rv-infodis
Scores
CVSS v3
5.3
EPSS
0.0120
EPSS Percentile
64.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-285
Status
published
Products (4)
cisco/rv016_multi-wan_vpn_firmware
< 4.2.3.10
cisco/rv042_dual_wan_vpn_firmware
< 4.2.3.10
cisco/rv042g_dual_gigabit_wan_vpn_firmware
< 4.2.3.10
cisco/rv082_dual_wan_vpn_firmware
< 4.2.3.10
Published
Nov 26, 2019
Tracked Since
Feb 18, 2026