CVE-2023-20073: Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-20073.
What is the severity of CVE-2023-20073?
The severity of CVE-2023-20073 is critical.
Which Cisco products are affected by CVE-2023-20073?
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers are affected by CVE-2023-20073.
How can an attacker exploit CVE-2023-20073?
An attacker can exploit CVE-2023-20073 by uploading arbitrary files to the affected device through the web-based management interface.
Is authentication required to exploit CVE-2023-20073?
No, authentication is not required to exploit CVE-2023-20073.