Improper Authorization in Cisco Systems, Inc products - CVE-2022-20702

 

Improper Authorization in Cisco Systems, Inc products - CVE-2022-20702

Published: February 2, 2022 / Updated: February 22, 2022


Vulnerability identifier: #VU60249
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20702
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to missing authorization within the utility-ping-request script in the web-management interface. A local user can execute arbitrary code with elevated privileges.

Affected software

Cisco RV345P Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco Small Business RV160 Series VPN Router
Cisco Small Business RV260W Wireless-AC VPN Router
Cisco Small Business RV260P VPN Router with POE
Cisco Small Business RV260 VPN Router
Cisco Small Business RV160W Wireless-AC VPN Router

How to mitigate CVE-2022-20702

Install updates from vendor's website.

Cisco RV345P Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV345 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router - update to 1.0.03.26

External References

Related Security Bulletins