Input validation error in Cisco Systems, Inc products - CVE-2020-3357

 

Input validation error in Cisco Systems, Inc products - CVE-2020-3357

Published: July 21, 2020


Vulnerability identifier: #VU31723
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3357
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input in the Secure Sockets Layer (SSL) VPN feature. A remote attacker can send a specially crafted HTTP request and execute arbitrary code on the target device or cause the device to reload, resulting in a denial of service (DoS) condition.


Affected software

Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV345P Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router

How to mitigate CVE-2020-3357

Install updates from vendor's website.

Cisco RV340 Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV345 Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV345P Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router - update to 1.0.03.18

External References

Related Security Bulletins