First published: Thu Feb 10 2022(Updated: )
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Rv340 Firmware | <=1.0.03.24 | |
Cisco RV340 | ||
Cisco Rv340w Firmware | <=1.0.03.24 | |
Cisco Rv340w | ||
Cisco Rv345 Firmware | <=1.0.03.24 | |
Cisco Rv345 | ||
Cisco Rv345p Firmware | <=1.0.03.24 | |
Cisco Rv345p | ||
All of | ||
Cisco Rv340 Firmware | <=1.0.03.24 | |
Cisco RV340 | ||
All of | ||
Cisco Rv340w Firmware | <=1.0.03.24 | |
Cisco Rv340w | ||
All of | ||
Cisco Rv345 Firmware | <=1.0.03.24 | |
Cisco Rv345 | ||
All of | ||
Cisco Rv345p Firmware | <=1.0.03.24 | |
Cisco Rv345p | ||
Cisco RV340 | ||
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20701 is a vulnerability that allows local attackers to escalate privileges on affected installations of Cisco RV340 routers.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers, as well as Cisco RV340, RV340w, RV345, and RV345p firmware versions up to 1.0.03.24 are affected.
CVE-2022-20701 has a severity value of 7.8, which is considered critical.
Cisco has released a security advisory containing information on how to mitigate this vulnerability. Please visit the reference link for more details.