PT-2021-2960 · Cisco · Cisco Rv345+3

T. Shiomitsu

·

Published

2021-05-05

·

Updated

2021-05-14

·

CVE-2021-1520

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco RV340, RV340W, RV345, and RV345P versions (affected versions not specified)
Description The issue is related to a buffer overflow in the messaging service of the affected routers, which could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system. This is due to the internal messaging service not properly sanitizing input. To exploit this, an attacker must first authenticate to the device and then send a crafted request to the internal service.
Recommendations For Cisco RV340, RV340W, RV345, and RV345P, consider restricting access to the internal messaging service until a patch is available. As a temporary workaround, avoid using the vulnerable vpntimer function until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02547
CVE-2021-1520

Affected Products

Cisco Rv340
Cisco Rv340W
Cisco Rv345
Cisco Rv345P