CVE-2020-3451

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/09/2020
Last modified:
07/11/2023

Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a restricted user. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* 1.0.03.19 (excluding)
cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* 1.0.03.19 (excluding)
cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* 1.0.03.19 (excluding)
cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* 1.0.03.19 (excluding)
cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*