PT-2020-3117 · Cisco · Cisco Small Business Rv340+3
0X00String
·
Published
2020-07-15
·
Updated
2021-08-06
·
CVE-2020-3357
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business RV340 versions
Cisco Small Business RV340W versions
Cisco Small Business RV345 versions
Cisco Small Business RV345P versions
Description
The issue exists due to insufficient validation of HTTP requests in the Secure Sockets Layer (SSL) VPN feature. This could allow a remote attacker to execute arbitrary code on an affected device or cause it to reload, resulting in a denial of service (DoS) condition. An attacker could exploit this by sending a crafted HTTP request over an SSL connection.
Recommendations
For Cisco Small Business RV340, update the firmware to a version that fixes the vulnerability.
For Cisco Small Business RV340W, update the firmware to a version that fixes the vulnerability.
For Cisco Small Business RV345, update the firmware to a version that fixes the vulnerability.
For Cisco Small Business RV345P, update the firmware to a version that fixes the vulnerability.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business Rv340
Cisco Small Business Rv340W
Cisco Small Business Rv345
Cisco Small Business Rv345P