First published: Thu Feb 10 2022(Updated: )
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Rv340 Firmware | <=1.0.03.24 | |
Cisco RV340 | ||
Cisco Rv340w Firmware | <=1.0.03.24 | |
Cisco Rv340w | ||
Cisco Rv345 Firmware | <=1.0.03.24 | |
Cisco Rv345 | ||
Cisco Rv345p Firmware | <=1.0.03.24 | |
Cisco Rv345p | ||
All of | ||
Cisco Rv340 Firmware | <=1.0.03.24 | |
Cisco RV340 | ||
All of | ||
Cisco Rv340w Firmware | <=1.0.03.24 | |
Cisco Rv340w | ||
All of | ||
Cisco Rv345 Firmware | <=1.0.03.24 | |
Cisco Rv345 | ||
All of | ||
Cisco Rv345p Firmware | <=1.0.03.24 | |
Cisco Rv345p | ||
Cisco RV340 | ||
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
All of | ||
<=1.0.03.24 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-20708.
The severity of CVE-2022-20708 is critical with a severity value of 9.8.
Network-adjacent attackers can exploit CVE-2022-20708 by executing arbitrary code on affected installations of Cisco RV340 routers after bypassing the authentication mechanism.
Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers, as well as Cisco RV340, are affected by CVE-2022-20708.
You can find more information about CVE-2022-20708 at the Cisco Security Advisory [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D] and Zero Day Initiative [https://www.zerodayinitiative.com/advisories/ZDI-22-417/] websites.