CVE-2022-20703: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Other sources
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID for this issue is CVE-2022-20703.
What is the severity of CVE-2022-20703?
The severity of CVE-2022-20703 is critical with a CVSS score of 8.8.
Which Cisco products are affected by CVE-2022-20703?
The Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers are affected by CVE-2022-20703.
Is user interaction required to exploit CVE-2022-20703?
Yes, user interaction is required to exploit CVE-2022-20703.
Are there any available references for more information about CVE-2022-20703?
Yes, you can find more information about CVE-2022-20703 at the following links: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D), [ZDI Advisory 22-408](https://www.zerodayinitiative.com/advisories/ZDI-22-408/), [ZDI Advisory 22-413](https://www.zerodayinitiative.com/advisories/ZDI-22-413/)