Input validation error in Cisco Systems, Inc products - CVE-2020-3358

 

Input validation error in Cisco Systems, Inc products - CVE-2020-3358

Published: July 21, 2020


Vulnerability identifier: #VU31724
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3358
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Secure Sockets Layer (SSL) VPN feature. A remote attacker can send a specially crafted HTTP request and perform a denial of service (DoS) attack.


Affected software

Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV345P Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router

How to mitigate CVE-2020-3358

Install updates from vendor's website.

Cisco RV340 Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV345 Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV345P Dual WAN Gigabit VPN Router - update to 1.0.03.18
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router - update to 1.0.03.18

External References

Related Security Bulletins