Junglewise Threat Intelligence

CVE-2022-20703: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

CVE-2022-20703 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco RV160, Cisco RV345 Series Routers, Cisco Small Business Rv160, Cisco RV340, Cisco RV260. Vendors: Cisco.

Executive brief

A stack-based buffer overflow vulnerability in Cisco Small Business RV Series routers allows a remote, unauthenticated attacker to execute arbitrary code, elevate privileges, or cause a denial of service. The flaw can also be leveraged to bypass authentication protections and run unsigned software.

Affected products

  • Cisco RV160 Series Routers
  • Cisco RV260 Series Routers
  • Cisco RV340 Series Routers from (including) 1.0.03.24
  • Cisco RV345 Series Routers from (including) 1.0.03.24

Timeline

  • 2022-03-03: disclosed
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: advisory

Related threats