CVE-2022-20699

Cisco Small Business RV Series Routers Vulnerabilities

Basic Information

CVE State
PUBLISHED
Reserved Date
November 02, 2021
Published Date
February 10, 2022
Last Updated
October 29, 2024
Vendor
Cisco
Product
Cisco Small Business RV Series Router Firmware
Description
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
Tags
cisa edge metasploit_scanner

CVSS Scores

CVSS v3.1

10.0 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2022-03-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2022-02-14 06:23:06 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-03-03 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

cisco_rv340_sslvpn

Type: metasploit • Created: Unknown

Metasploit module for CVE-2022-20699

rohan-flutterint/CVE-2022-20699

Type: github • Created: 2022-02-14 06:23:06 UTC • Stars: 4

Audiobahn/CVE-2022-20699

Type: github • Created: 2022-02-07 15:53:21 UTC • Stars: 240

Cisco Anyconnect VPN unauth RCE (rwx stack)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Metasploit