CVE-2022-20841
published 2022-08-10CVE-2022-20841: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute…
PriorityP266critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
2.93%
85.6th percentile
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv160_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv160w_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260p_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv260w_firmware | < 1.0.01.05 | 1.0.01.05 |
| cisco | rv340_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv340w_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv345_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | rv345p_firmware | < 1.0.03.26 | 1.0.03.26 |
| cisco | small_business_rv_series_routers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-20841 affects Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers; unauthenticated remote attackers can execute arbitrary code or cause DoS — monitor for unexpected inbound connections and command injection attempts targeting these device families ↗
- →Vulnerability classes include buffer overflow (CWE-120) and OS command injection (CWE-77, CWE-78); detection should focus on anomalous process spawning or shell execution from router management processes ↗
- ·No workarounds are available; the only mitigation is applying Cisco's released software updates for affected RV160, RV260, RV340, and RV345 Series Routers ↗
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·2022-08-03·CVSS 9.8
CVE-2022-20827 [CRITICAL] CWE-120 Cisco Small Business RV Series Routers Vulnerabilities
Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-mult-vuln-CbVp4SUR
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20841 Cisco Small Business RV Series Routers Vulnerabilities
CVE-2022-20841: Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-77, CWE-78, CWE-120, CWE-77, CWE-78
Bug IDs: CSCwb58268, CSCwb58273, CSCwb98961, CSCwb58268, CSCwb58273
GHSA
GHSA-x2h4-3j4q-4xqv: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exec
ghsa_unreviewed·2022-08-11
CVE-2022-20841 [CRITICAL] CWE-20 GHSA-x2h4-3j4q-4xqv: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to exec
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Security Feature Bypass Vulnerabilities Addressed
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Evaluate Vendor-Suggested Workarounds With Policy Compliance
- Patch Tuesday is Complete.
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft
Qualys
August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
blogs_qualys·2022-08-09·CVSS 6.5
[MEDIUM] August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities With 17 Critical, Plus 20 Microsoft Edge (Chromium-Based); Adobe Releases 5 Advisories, 25 Vulnerabilities With 15 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The August 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Security Feature Bypass Vulnerabilities Addressed
Microsoft Critical and Important Vulnerability Highlights
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Protection High-Rated Advisories for August 1-9, 2022
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Evaluate Vendor-Suggested Workarounds With Policy Compliance
Patch Tuesday is Complete.
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Sum
2022-08-10
Published