CVE-2024-20393

CWE-285CWE-1464 documents4 sources
Severity
8.8HIGH
EPSS
1.4%
top 19.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2

Description

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists because the web-based management interface discloses sensitive information. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow an attacker to elevate privileges f

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
CVEList
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Privilege Escalation Vulnerability2024-10-02
GHSA
GHSA-95px-w8x3-2w55: A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allo2024-10-02

📋Vendor Advisories

1
Cisco
Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Privilege Escalation and Remote Command Execution Vulnerabilities2024-10-02
CVE-2024-20393 (HIGH CVSS 8.8) | A vulnerability in the web-based ma | cvebase.io