CVE-2022-20749
Published on: 02/10/2022 12:00:00 AM UTC
Last Modified on: 02/17/2022 05:09:00 PM UTC
CVE-2022-20749 - advisory for cisco-sa-smb-mult-vuln-KA9PK6D
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Rv340 from Cisco contain the following vulnerability:
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2022-20749 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- The Cisco PSIRT is aware that proof-of-concept exploit code is available for several of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Small Business RV Series Router Firmware version n/a
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
No Description Provided | tools.cisco.com text/html |
![]() |
Related QID Numbers
- 730347 Cisco Small Business RV (340|345) Series Routers Vulnerabilities (cisco-sa-smb-mult-vuln-KA9PK6D)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | Rv340 | - | All | All | All |
Hardware
| Cisco | Rv340w | - | All | All | All |
Operating System | Cisco | Rv340w Firmware | All | All | All | All |
Operating System | Cisco | Rv340 Firmware | All | All | All | All |
Hardware
| Cisco | Rv345 | - | All | All | All |
Hardware
| Cisco | Rv345p | - | All | All | All |
Operating System | Cisco | Rv345p Firmware | All | All | All | All |
Operating System | Cisco | Rv345 Firmware | All | All | All | All |
- cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Cisco.Multiple Vulnerabilities in Small Business RV Series Routers -3/3 CVE-2022-20710 CVE-2022-20711 CVE-2022-20712 CVE-2022-20749 | 2022-02-03 04:09:05 |
![]() |
CVE-2022-20749 : Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers cou… twitter.com/i/web/status/1… | 2022-02-10 18:12:15 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Cisco Products Could Allow for Arbitrary Code Execution - PATCH: NOW | 2022-02-03 14:33:12 |
![]() |
CVE-2022-20749 | 2022-02-10 18:39:08 |