Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers SSL Denial of Service Vulnerability

cisco-sa-sb-dos-ZN5GvNH7 · High · Published · Updated

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to the targeted device. A successful exploit could allow the attacker to cause a reload, resulting in a DoS condition. Cisco has released software updates that address the vulnerability described in this advisory. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-dos-ZN5GvNH7

Cisco advisory · CSAF JSON

Workarounds

Disabling the SSL VPN configuration eliminates the attack vector for this vulnerability, and may be a suitable mitigation until the affected device can be upgraded. The administrator can use the web-based utility to navigate to VPN > SSL VPN and set the radio button to Off.

CVEsCVE-2020-3358
Cisco Bug IDsCSCvu36544
CVSS ScoreBase 8.6
Base 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Small Business RV Series Router Firmware

Related Products

Product CVE Evidence
Cisco Small Business RV Series Router Firmware CVE-2020-3358 Cisco OpenVuln