CVE-2024-20393
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-20393 is a recently disclosed vulnerability affecting the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers. The issue permits an authenticated, remote attacker to escalate privileges on the device. This vulnerability arises due to the interface's disclosure of sensitive information. An attacker can exploit this weakness by crafting targeted HTTP inputs, potentially upgrading their access level from guest to admin. It is crucial for organizations using these devices to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco