Improper Neutralization of Expression/Command Delimiters in Cisco Systems, Inc products - CVE-2024-20470

 

Improper Neutralization of Expression/Command Delimiters in Cisco Systems, Inc products - CVE-2024-20470

Published: October 4, 2024


Vulnerability identifier: #VU98035
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20470
CWE-ID: CWE-146
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to the web-based management interface does not sufficiently validate user-supplied input. A remote administrator can send a specially crafted HTTP request and execute arbitrary code as the root user on the underlying operating system.


Affected software

Cisco RV340 Dual WAN Gigabit VPN Router
Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router
Cisco RV345 Dual WAN Gigabit VPN Router
RV345P Dual WAN Gigabit PoE VPN Router

How to mitigate CVE-2024-20470

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins