CVE-2022-20827
published 2022-08-10CVE-2022-20827: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute…
PriorityP270critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.70%
74.6th percentile
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv160_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv160w_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260p_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260w_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv340_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv340w_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv345_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv345p_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | small_business_rv_series_routers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-20827 affects Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers and allows unauthenticated remote code execution or DoS; monitor these device models for unexpected outbound connections or process spawning ↗
- →CWE-78 (OS Command Injection) and CWE-77 (Command Injection) are root causes; look for anomalous shell command execution originating from router management processes ↗
- →Track Cisco Bug IDs CSCwb58268, CSCwb58273, CSCwb98961 for patch status and exploit PoC disclosures related to this CVE ↗
- ·No workarounds are available; the only mitigation is applying Cisco's software updates ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·2022-08-03·CVSS 9.8
CVE-2022-20827 [CRITICAL] CWE-120 Cisco Small Business RV Series Routers Vulnerabilities
Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-mult-vuln-CbVp4SUR
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20827 Cisco Small Business RV Series Routers Vulnerabilities
CVE-2022-20827: Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-77, CWE-78, CWE-120, CWE-77, CWE-78
Bug IDs: CSCwb58268, CSCwb58273, CSCwb98961, CSCwb58268, CSCwb58273
GHSA
GHSA-566p-j792-hxrj: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exec
ghsa_unreviewed·2022-08-11
CVE-2022-20827 [CRITICAL] CWE-78 GHSA-566p-j792-hxrj: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exec
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Security Feature Bypass Vulnerabilities Addressed
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Evaluate Vendor-Suggested Workarounds With Policy Compliance
- Patch Tuesday is Complete.
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Security Feature Bypass Vulnerabilities Addressed
Microsoft Critical and Important Vulnerability Highlights
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Evaluate Vendor-Suggested Workarounds With Policy Compliance
Patch Tuesday is Complete.
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Sum
2022-08-10
Published