Improper Authentication in Cisco Systems, Inc products - CVE-2022-20705
Published: February 2, 2022 / Updated: February 15, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the session management of the web UI. A remote non-authenticated attacker can brute force to determine a current session identifier and then reuse it to take over an ongoing session or by crafting a new, valid session identifier and bypassing the whole authentication mechanism.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected device.Affected software
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco Small Business RV160 Series VPN Router
Cisco Small Business RV260W Wireless-AC VPN Router
Cisco Small Business RV260P VPN Router with POE
Cisco Small Business RV260 VPN Router
Cisco Small Business RV160W Wireless-AC VPN Router
How to mitigate CVE-2022-20705
Cisco RV345 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340 Dual WAN Gigabit VPN Router - update to 1.0.03.26
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router - update to 1.0.03.26