PT-2020-3117 · Cisco · Cisco Small Business Rv340+3

0X00String

·

Published

2020-07-15

·

Updated

2021-08-06

·

CVE-2020-3357

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Small Business RV340 versions Cisco Small Business RV340W versions Cisco Small Business RV345 versions Cisco Small Business RV345P versions
Description The issue exists due to insufficient validation of HTTP requests in the Secure Sockets Layer (SSL) VPN feature. This could allow a remote attacker to execute arbitrary code on an affected device or cause it to reload, resulting in a denial of service (DoS) condition. An attacker could exploit this by sending a crafted HTTP request over an SSL connection.
Recommendations For Cisco Small Business RV340, update the firmware to a version that fixes the vulnerability. For Cisco Small Business RV340W, update the firmware to a version that fixes the vulnerability. For Cisco Small Business RV345, update the firmware to a version that fixes the vulnerability. For Cisco Small Business RV345P, update the firmware to a version that fixes the vulnerability.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03409
CVE-2020-3357

Affected Products

Cisco Small Business Rv340
Cisco Small Business Rv340W
Cisco Small Business Rv345
Cisco Small Business Rv345P