CERT-In Vulnerability Note
CIVN-2022-0306
Multiple vulnerabilities in Cisco Products
Original Issue Date:July 22, 2022
Severity Rating: MEDIUM
Component Affected
- RV110W Wireless-N VPN Firewall
- RV130 VPN Router
- RV130W Wireless-N Multifunction VPN Router
- RV215W Wireless-N VPN Router
Overview
Multiple vulnerabilities have been reported in Cisco products which could allow an authenticated remote attacker to execute arbitrary code or cause a denial-of-service (DoS) condition on the targeted system.
Description
These vulnerabilities exist in Cisco products due to improper validation of user fields within incoming HTTP requests. An authenticated remote attacker could exploit these vulnerabilities by sending specially crafted requests to the web-based management interface.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or cause a denial-of-service (DoS) condition on the targeted system.
Solution
Apply appropriate software updates as mentioned in the below link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-rce-overflow-ygHByAK
Vendor Information
Cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-rce-overflow-ygHByAK
References
Cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-rce-overflow-ygHByAK
CVE Name
CVE-2022-20873
CVE-2022-20874
CVE-2022-20875
CVE-2022-20876
CVE-2022-20877
CVE-2022-20878
CVE-2022-20879
CVE-2022-20880
CVE-2022-20881
CVE-2022-20882
CVE-2022-20883
CVE-2022-20884
CVE-2022-20885
CVE-2022-20886
CVE-2022-20887
CVE-2022-20888
CVE-2022-20889
CVE-2022-20890
CVE-2022-20891
CVE-2022-20892
CVE-2022-20893
CVE-2022-20894
CVE-2022-20895
CVE-2022-20896
CVE-2022-20897
CVE-2022-20898
CVE-2022-20899
CVE-2022-20900
CVE-2022-20901
CVE-2022-20902
CVE-2022-20903
CVE-2022-20904
CVE-2022-20910
CVE-2022-20911
CVE-2022-20912
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|