Junglewise Threat Intelligence

CVE-2022-20700: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

CVE-2022-20700 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco RV160, Cisco RV345 Series Routers, Cisco Small Business Rv160, Cisco RV340, Cisco RV260. Vendors: Cisco.

Executive brief

A stack-based buffer overflow vulnerability in Cisco Small Business RV Series routers allows a remote, unauthenticated attacker to execute arbitrary code, elevate privileges, or cause a denial of service. The flaw stems from insufficient bounds checking when processing network traffic, potentially leading to full system compromise.

Affected products

  • Cisco RV160 Series Routers up to (including) 1.0.01.05
  • Cisco RV260 Series Routers up to (including) 1.0.01.05
  • Cisco RV340 Series Routers up to (including) 1.0.03.24
  • Cisco RV345 Series Routers up to (including) 1.0.03.24

Timeline

  • 2022-02-17: disclosed: Initial analysis by NIST
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: exploited: Reported as exploited in the wild

Related threats