← All CVEs

CVE-2022-20703

critical · 10Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-17

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

10
CVSS
9.2%
EPSS (exploit prob.)
95th
EPSS percentile
2022-02-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-121CWE-295

Affected products

VendorProductAffected versions
ciscorv340_firmware<= 1.0.03.24
ciscorv340all versions
ciscorv340w_firmware<= 1.0.03.24
ciscorv340wall versions
ciscorv345_firmware<= 1.0.03.24
ciscorv345all versions
ciscorv345p_firmware<= 1.0.03.24
ciscorv345pall versions
ciscorv160_firmware<= 1.0.01.05
ciscorv160all versions
ciscorv160w_firmware<= 1.0.01.05
ciscorv160wall versions
ciscorv260_firmware<= 1.0.01.05
ciscorv260all versions
ciscorv260p_firmware<= 1.0.01.05
ciscorv260pall versions
ciscorv260w_firmware<= 1.0.01.05
ciscorv260wall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-20703