CVE-2023-20073
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability
Record summary
CVE-2023-20073 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 15, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Cisco Small Business RV Series Router FirmwareBrowse Cisco / Cisco Small Business RV Series Router Firmware | CVE List | Version range not supplied | affected |
RV Series RoutersBrowse Cisco / RV Series Routers | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubRegularITCat/CVE-2023-20073Repository PoCby RegularITCatStars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALCisco VPN Routers - Unauthenticated Arbitrary File UploadCVSS 9.8
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.
Impact
Successful exploitation of this vulnerability could lead to remote code execution or unauthorized access to sensitive information.
Remediation
Apply the latest security patches provided by Cisco to mitigate this vulnerability.
Source: ProjectDiscovery