cbcvebase.
CVE-2022-20923
published 2022-09-08

CVE-2022-20923: A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.87%
54.5th percentile
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network. This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to the VPN from an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and access the IPSec VPN network. The attacker may obtain privileges that are the same level as an administrative user, depending on the crafted credentials that are used. Cisco has not released software updates that address this vulnerability.

Affected

14 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_rv_series_router_firmware
ciscorv110w_firmware
ciscorv110w_firmware
ciscorv110w_firmware
ciscorv130_firmware
ciscorv130_firmware
ciscorv130_firmware
ciscorv130w_firmware
ciscorv130w_firmware
ciscorv130w_firmware
ciscorv215w_firmware
ciscorv215w_firmware
ciscorv215w_firmware
ciscosmall_business_rv110w_rv130_rv130w_and_rv215w_routers_ipsec_vpn_server

Detection & IOCsextracted from sources · hover to see the quote

  • Target vector is IPSec VPN Server authentication on Cisco Small Business RV110W, RV130, RV130W, and RV215W routers — monitor for unauthenticated or anomalous IKE/IPSec login attempts against these device models
  • Attacker may authenticate with administrative-level privileges via crafted credentials — alert on unexpected administrative VPN sessions on affected router models
  • Track Cisco Bug IDs CSCwc57640, CSCwc57664, CSCwc57666 for patch/signature updates related to this authentication bypass
  • ·No software fix is available from Cisco; no workarounds exist — affected devices (RV110W, RV130, RV130W, RV215W) running IPSec VPN Server remain permanently vulnerable until replaced or isolated
  • ·Root cause is improper implementation of the password validation algorithm (CWE-303) — any credential-based detection must account for the fact that crafted/malformed passwords may pass validation on these devices

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.