CVE-2022-20753
published 2022-05-04CVE-2022-20753: A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute…
PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.08%
79.5th percentile
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute remote code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv340_firmware | < 1.0.03.27 | 1.0.03.27 |
| cisco | rv340w_firmware | < 1.0.03.27 | 1.0.03.27 |
| cisco | rv345_firmware | < 1.0.03.27 | 1.0.03.27 |
| cisco | rv345p_firmware | < 1.0.03.27 | 1.0.03.27 |
| cisco | small_business_rv_series_routers | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
cisa9.8CRITICAL
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
vendor_cisco·2022-05-04·CVSS 4.7
CVE-2022-20753 [MEDIUM] CWE-121 Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute remote code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is ava
CISA
Kaseya VSA Remote Code Execution Vulnerability
cisa·2022-04-13·CVSS 9.8
CVE-2018-20753 [CRITICAL] Kaseya VSA Remote Code Execution Vulnerability
Vulnerability: Kaseya VSA Remote Code Execution Vulnerability
Affected: Kaseya Virtual System/Server Administrator (VSA)
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-20753
Remediation Due Date: 2022-05-04
Cisco
Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20753 Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
CVE-2022-20753: Cisco Small Business RV Series Routers Remote Code Execution Vulnerability
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute remote code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-121, CWE-121
Bug IDs: CSCwa64992
GHSA
GHSA-x2hp-jfj2-m3hc: A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to exe
ghsa_unreviewed·2022-05-05
CVE-2022-20753 [HIGH] CWE-787 GHSA-x2hp-jfj2-m3hc: A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to exe
A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute remote code on the affected device. To exploit this vulnerability, an attacker would need to have valid Administrator credentials on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-04
Published