Record summary

CVE-2023-20073 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 15, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 28, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Cisco Small Business RV Series Router Firmware

Browse Cisco / Cisco Small Business RV Series Router Firmware
CVE ListVersion range not suppliedaffected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubRegularITCat/CVE-2023-20073Repository PoCby RegularITCatStars: 1Not analyzed2 files

914 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALCisco VPN Routers - Unauthenticated Arbitrary File UploadCVSS 9.8

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.

Impact

Successful exploitation of this vulnerability could lead to remote code execution or unauthorized access to sensitive information.

Remediation

Apply the latest security patches provided by Cisco to mitigate this vulnerability.

WeaknessesCWE-434
Authorsprincechaddha, ritikchaddha
Template tagscve2023cvexssfileuploadciscounauthroutersvpnintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*
FOFA: app="CISCO-RV340" || app="CISCO-RV340W" || app="CISCO-RV345" || app="CISCO-RV345P"
FOFA: app="cisco-rv340" || app="cisco-rv340w" || app="cisco-rv345" || app="cisco-rv345p"

Source: ProjectDiscovery

References

2