Junglewise Threat Intelligence

CVE-2022-20699: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

CVE-2022-20699 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco RV160, Cisco RV345 Series Routers, Cisco Small Business Rv160, Cisco RV340, Cisco RV260. Vendors: Cisco.

Executive brief

A stack-based buffer overflow vulnerability in Cisco Small Business RV Series routers allows an unauthenticated, remote attacker to execute arbitrary code, elevate privileges, or cause a denial of service. The vulnerability stems from improper validation of input quantity, potentially allowing the execution of unsigned software or the bypassing of authentication protections.

Affected products

  • Cisco RV160 Series Routers
  • Cisco RV260 Series Routers
  • Cisco RV340 Series Routers
  • Cisco RV345 Series Routers

Timeline

  • 2022-03-03: disclosed
  • 2022-03-03: advisory
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: exploited: Reported as exploited in the wild at time of publication.

Related threats