cbcvebase.
CVE-2020-3451
published 2020-09-04

CVE-2020-3451: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with…

PriorityP278medium4.7CVSS 3.1
AVNACLPRHUINSUCLILAL
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.17%
80.3th percentile
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a restricted user. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_rv_series_router_firmware
ciscorv340_firmware< 1.0.03.191.0.03.19
ciscorv340w_firmware< 1.0.03.191.0.03.19
ciscorv345_firmware< 1.0.03.191.0.03.19
ciscorv345p_firmware< 1.0.03.191.0.03.19
ciscosmall_business_rv340_series_routers

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability targets the web-based management interface of Cisco Small Business RV340 Series Routers; monitor for unexpected or anomalous HTTP/HTTPS requests to the management interface that may contain OS command injection payloads
  • Track Cisco Bug IDs CSCvu40103 and CSCvu49391 for patch status and vendor-specific detection signatures related to this CVE
  • ·The NVD description states the attacker must be authenticated with administrative credentials, while the Cisco advisory states the attacker can be unauthenticated — verify the correct authentication requirement against the latest vendor advisory before tuning detection rules
  • ·Cisco confirms there are no workarounds available; patching via software update is the only remediation, meaning unpatched devices remain fully exposed

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck4.7MEDIUM
vendor_cisco7.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.