Improper access control in Cisco Systems, Inc products - CVE-2020-3144
Published: July 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the web-based management interface. A remote attacker can send s specially crafted HTTP request, bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
Cisco Small Business RV130 Series VPN Routers
RV215W Wireless-N VPN Router
RV110W Wireless-N VPN Firewall
How to mitigate CVE-2020-3144
Cisco Small Business RV130 Series VPN Routers - update to 1.0.3.55
RV215W Wireless-N VPN Router - update to 1.3.1.7
RV110W Wireless-N VPN Firewall - update to 1.2.2.8