PT-2021-2960 · Cisco · Cisco Rv345+3
T. Shiomitsu
·
Published
2021-05-05
·
Updated
2021-05-14
·
CVE-2021-1520
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco RV340, RV340W, RV345, and RV345P versions (affected versions not specified)
Description
The issue is related to a buffer overflow in the messaging service of the affected routers, which could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system. This is due to the internal messaging service not properly sanitizing input. To exploit this, an attacker must first authenticate to the device and then send a crafted request to the internal service.
Recommendations
For Cisco RV340, RV340W, RV345, and RV345P, consider restricting access to the internal messaging service until a patch is available.
As a temporary workaround, avoid using the vulnerable
vpntimer function until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Rv340
Cisco Rv340W
Cisco Rv345
Cisco Rv345P