Back to overview

CVE-2022-20707

CRITICAL
10.0
CVSS 3.1
Description
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

Metadata

CVE ID
CVE-2022-20707
State
PUBLISHED
Assigner
cisco
Reserved
2021-11-02 00:00 UTC
Published
2022-02-10 17:06 UTC
Last updated
2024-11-06 16:31 UTC
Primary CWE
CWE-121
CWE-121
Vendor / Product
Cisco / Cisco Small Business RV Series Router Firmware
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Small Business RV Series Router Firmware n/a
Weakness (CWE)
CWESourceDescription
CWE-121 cna CWE-121
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview