Cisco has released software updates that address multiple vulnerabilities in Cisco Small Business VPN routers which allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.
The vulnerabilities tracked as CVE-2022-20827 and CVE-2022-20841 affect the following Cisco products:
The vulnerability tracked as CVE-2022-20842 affects the following Cisco products:
In an advisory, Cisco noted that “The vulnerabilities are dependent on one another. Exploitation of one of the vulnerabilities may be required to exploit another vulnerability”.
“In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities”.
The flaw is tracked as (CVE-2022-20842) with the CVSS Base Score: 9.8, found in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers.
Upon successful exploitation of the vulnerability could allow an attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device.
The advisory mention that “The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface”.
This vulnerability is tracked as (CVE-2022-20827) with the CVSS Base Score: 9.0 found in the web filter database update feature of Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers.
This could allow an unauthenticated, remote attacker to perform a command injection and execute commands on the underlying operating system with root privileges. It is due to insufficient input validation.
“An attacker could exploit this vulnerability by submitting crafted input to the web filter database update feature”, the advisory stated.
This flaw is tracked as (CVE-2022-20841) with the CVSS Base Score: 8.3 found in the Open Plug and Play (PnP) module of Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers.
The flaw could allow an attacker to inject and execute arbitrary commands on the underlying operating system. It is due to insufficient validation of user-supplied input. Upon successful exploitation, this could allow the attacker to execute arbitrary commands on the underlying Linux operating system.
Cisco says “An attacker must leverage a man-in-the-middle position or have an established foothold on a specific network device that is connected to the affected router”.
CVE-2022-20827 and CVE-2022-20841
Cisco Product | Affected Releases | First Fixed Release |
RV160 and RV260 Series Routers | Earlier than 1.0.01.05 | Not vulnerable |
RV160 and RV260 Series Routers | 1.0.01.05 | 1.0.01.09 |
RV340 and RV345 Series Routers | Earlier than 1.0.03.26 | Not vulnerable |
RV340 and RV345 Series Routers | 1.0.03.26 | 1.0.03.28 |
CVE-2022-20842
Cisco Product | Affected Releases | First Fixed Release |
RV340 and RV345 Series Routers | 1.0.03.26 and earlier | 1.0.03.28 |
Cisco has released patches for three vulnerabilities which are rated ‘Critical’ and ‘High’ in severity. Cisco recommends upgrading to an appropriate fixed software release and there are no workarounds that address these vulnerabilities.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting victims…
The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ advanced…
A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to execute…
Meta has announced the removal of over 2 million accounts connected to malicious activities, including…
Critical security vulnerability has been identified in Veritas Enterprise Vault, a widely-used archiving and content…
A critical security vulnerability has been disclosed in the popular file archiving tool 7-Zip, allowing…