ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-20842CVE-2022-20827CVE-2022-20841

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-20827
+1 in the same advisory: …20841
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitr

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

NVD description · AI analysis pending
10.0
group max
2%
  • cisco rv160 firmware
  • cisco rv160w firmware
  • cisco rv260 firmware
  • +1 more
CVE-2022-20842
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitr

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

NVD description · AI analysis pending
9.82%
  • cisco rv340 firmware
  • cisco rv340w firmware
  • cisco rv345 firmware
  • +1 more
Full article330 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 04, 2022

Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution (RCE) or cause a denial-of-service (DoS) condition on affected devices.

The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers. Tracked as CVE-2022-20842 (CVSS score: 9.8), the weakness stems from an insufficient validation of user-supplied input to the web-based management interface of the appliances.

"An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device," Cisco said in an advisory. "A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition."

A second shortcoming relates to a command injection vulnerability residing in the routers' web filter database update feature (CVE-2022-20827, CVSS score: 9.0), which could be exploited by an adversary to inject and execute arbitrary commands on the underlying operating system with root privileges.

The third router-related flaw to be resolved (CVE-2022-20841, CVSS score: 8.0) is also a command injection bug in the Open Plug-n-Play (PnP) module that could be abused by sending a malicious input to achieve code execution on the targeted Linux host.

"To exploit this vulnerability, an attacker must leverage a man-in-the-middle position or have an established foothold on a specific network device that is connected to the affected router," the networking equipment maker noted.

Also patched by Cisco are five medium security flaws affecting Webex Meetings, Identity Services Engine, Unified Communications Manager, and BroadWorks Application Delivery Platform.

The company offered no workarounds to remediate the issues, adding there is no evidence of these vulnerabilities being exploited in the wild. That said, customers are recommended to move quickly to apply the updates.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/cisco-business-routers-found-vulnerable.html