6.5

CVE-2021-1414

Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Authenticated Remote Code Execution Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service process on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Rv340 Firmware Version < 1.0.03.21
   Cisco ≫ Rv340 Version -
Cisco ≫ Rv340w Firmware Version < 1.0.03.21
   Cisco ≫ Rv340w Version -
Cisco ≫ Rv345 Firmware Version < 1.0.03.21
   Cisco ≫ Rv345 Version -
Cisco ≫ Rv345p Firmware Version < 1.0.03.21
   Cisco ≫ Rv345p Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.86% 0.765
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Cisco PSIRT 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-559/
Third Party Advisory
VDB Entry