Junglewise Threat Intelligence

CVE-2022-20708: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

CVE-2022-20708 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco RV160, Cisco RV345 Series Routers, Cisco Small Business Rv160, Cisco RV340, Cisco RV260. Vendors: Cisco.

Executive brief

A stack-based buffer overflow vulnerability in Cisco Small Business RV Series routers (RV160, RV260, RV340, and RV345) allows a remote attacker to execute arbitrary code, elevate privileges, or cause a denial of service. The flaw can also be leveraged to bypass authentication and run unsigned software.

Affected products

  • Cisco RV160 Series Routers
  • Cisco RV260 Series Routers
  • Cisco RV340 Series Routers up to and including 1.0.03.24
  • Cisco RV345 Series Routers up to and including 1.0.03.24

Timeline

  • 2022-02-17: disclosed: Initial analysis by NIST
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: advisory: Publication date of the advisory

Related threats