#VU67072 Incorrect implementation of authentication algorithm in Cisco Systems, Inc products - CVE-2022-20923
Published: September 8, 2022
RV110W Wireless-N VPN Firewall
Cisco Small Business RV130 Series VPN Routers
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the password validation algorithm in IPSec VPN Server authentication functionality. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to the IPSec VPN network.
Remediation
The affected routers are no longer supported by the vendor and Cisco will not release any security patches to address this vulnerability. It is recommended to replace the affected devices.