Back to overview

CVE-2022-20701

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 3.1
Description
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

Metadata

CVE ID
CVE-2022-20701
State
PUBLISHED
Assigner
cisco
Reserved
2021-11-02 00:00 UTC
Published
2022-02-10 17:06 UTC
Last updated
2025-10-21 23:15 UTC
Primary CWE
CWE-121
CWE-121
Vendor / Product
Cisco / Cisco Small Business RV Series Router Firmware
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
Vendor
Cisco
Product
Small Business RV160, RV260, RV340, and RV345 Series Routers
Added to KEV
2022-03-03
Due date
2022-03-17
Ransomware
Not known
Required action
Apply updates per vendor instructions.
CISA description
A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Small Business RV Series Router Firmware n/a
Weakness (CWE)
CWESourceDescription
CWE-121 cna CWE-121
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview