Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3286


Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.


Published

2020-06-18T03:15:12.730

Last Modified

2024-11-21T05:30:43.687

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco rv016_firmware ≤ 4.2.3.10 Yes
Hardware cisco rv016 - No
Operating System cisco rv042_firmware ≤ 4.2.3.10 Yes
Hardware cisco rv042 - No
Operating System cisco rv042g_firmware ≤ 4.2.3.10 Yes
Hardware cisco rv042g - No
Operating System cisco rv082_firmware ≤ 4.2.3.10 Yes
Hardware cisco rv082 - No
Operating System cisco rv320_firmware ≤ 1.5.1.05 Yes
Hardware cisco rv320 - No
Operating System cisco rv325_firmware ≤ 1.5.1.05 Yes
Hardware cisco rv325 - No

References