Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2022-20703

 

Improper Verification of Cryptographic Signature in Cisco Systems, Inc products - CVE-2022-20703

Published: February 2, 2022 / Updated: March 8, 2022


Vulnerability identifier: #VU60250
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20703
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows an attacker to compromise the affected device.

The vulnerability exists due to improper cryptographic signature verification of software images as they are installed on an affected device.An attacker with physical access to device can install and boot a malicious software image or execute unsigned binaries on an affected device.

Affected software

Cisco RV345P Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco Small Business RV160 Series VPN Router
Cisco Small Business RV260W Wireless-AC VPN Router
Cisco Small Business RV260P VPN Router with POE
Cisco Small Business RV260 VPN Router
Cisco Small Business RV160W Wireless-AC VPN Router

How to mitigate CVE-2022-20703

Install updates from vendor's website.

Cisco RV345P Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV345 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router - update to 1.0.03.26

External References

Related Security Bulletins