Arbitrary file upload in Cisco Systems, Inc products - CVE-2023-20073
Published: February 1, 2023 / Updated: August 20, 2023
Vulnerability identifier: #VU71741
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20073
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to upload arbitrary files to an affected device.
The vulnerability exists due to insufficient validation of file during file upload. A remote attacker can upload arbitrary files to an affected device.
Affected software
Cisco RV345P Dual WAN Gigabit VPN Router
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
How to mitigate CVE-2023-20073
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.