#VU98034 Improper Authorization in Cisco Systems, Inc products - CVE-2024-20393

 

#VU98034 Improper Authorization in Cisco Systems, Inc products - CVE-2024-20393

Published: October 4, 2024


Vulnerability identifier: #VU98034
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-20393
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
RV345P Dual WAN Gigabit PoE VPN Router
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to insufficient authorization controls in the web-based management interface. A remote user can send specially crafted HTTP input and elevate privileges from guest to admin.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links