CVE-2024-20416

A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulner

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.009
57.0th percentile
Discovered by
Third party
Vendor-published field
Published
Jul 17, 2024
Assigned by cisco

Description

A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient boundary checks when processing specific HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the device.

Weakness: CWE-130

Affected products

Vendor Product Category Matched by
Cisco Cisco Small Business Routers and Switches Routing & Switching cna-assigner
Vendor-reported products (5)
  • Cisco · Cisco Small Business RV Series Router Firmware
  • cisco · rv340_dual_wan_gigabit_vpn_router_firmware
  • cisco · rv345_dual_wan_gigabit_vpn_router_firmware
  • cisco · rv345p_dual_wan_gigabit_poe_vpn_router_firmware
  • cisco · rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware

Vendor advisory

cisco-sa-sb-rv34x-rce-7pqFU2e

Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers Authenticated Remote Code Execution Vulnerability

Cisco’s rating: Medium (advisory CVSS 6.5) · Published Jul 17, 2024

Bug ID: CSCwk32012

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?