HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-20470

CVSS 7.2v3.1pub. 2024-10-02upd. 2024-10-09

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this vulnerability, the attacker must have valid admin credentials. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Cisco Rv340 Dual Wan Gigabit Vpn Router

    HW
    Cisco
    all versions
  • Cisco Rv340 Dual Wan Gigabit Vpn Router Firmware

    OS
    Cisco
    1.0.00.291.0.00.331.0.01.161.0.01.171.0.01.181.0.01.201.0.02.161.0.03.151.0.03.161.0.03.171.0.03.181.0.03.191.0.03.201.0.03.211.0.03.22+ 5 more
  • Cisco Rv340w Dual Wan Gigabit Wireless Ac Vpn Router

    HW
    Cisco
    all versions
  • Cisco Rv340w Dual Wan Gigabit Wireless Ac Vpn Router Firmware

    OS
    Cisco
    1.0.00.291.0.00.331.0.01.161.0.01.171.0.01.181.0.01.201.0.02.161.0.03.151.0.03.161.0.03.171.0.03.181.0.03.191.0.03.201.0.03.211.0.03.22+ 5 more
  • Cisco Rv345 Dual Wan Gigabit Vpn Router

    HW
    Cisco
    all versions
  • Cisco Rv345 Dual Wan Gigabit Vpn Router Firmware

    OS
    Cisco
    1.0.00.291.0.00.331.0.01.161.0.01.171.0.01.181.0.01.201.0.02.161.0.03.151.0.03.161.0.03.171.0.03.181.0.03.191.0.03.201.0.03.211.0.03.22+ 5 more
  • Cisco Rv345p Dual Wan Gigabit Poe Vpn Router

    HW
    Cisco
    all versions
  • Cisco Rv345p Dual Wan Gigabit Poe Vpn Router Firmware

    OS
    Cisco
    1.0.00.291.0.00.331.0.01.161.0.01.171.0.01.181.0.01.201.0.02.161.0.03.151.0.03.161.0.03.171.0.03.181.0.03.191.0.03.201.0.03.211.0.03.22+ 5 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEVPN
CWE
References

Related vulnerabilities

CVE-2020-3357CRITICAL9.8PL ✓same product

RCE i DoS w funkcji SSL VPN routerów Cisco Small Business RV340/RV345

CVE-2024-20393HIGH8.8same product

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P...

CVE-2020-3358HIGH8.6same product

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could al...

CVE-2026-20182CRITICAL10.0⚠ KEVPL ✓same vendor

Cisco Catalyst SD-WAN — pominięcie uwierzytelnienia z dostępem administracyjnym

CVE-2026-20131CRITICAL10.0⚠ KEVPL ✓same vendor

RCE przez insecure deserialization w Cisco Secure Firewall Management Center