CVE-2024-20516

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 787
CWE ID 122

Summary

CVE-2024-20516 is a vulnerability affecting the web-based management interfaces of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue allows authenticated, Administrator-level, remote attackers to trigger an unexpected reload, leading to a denial of service (DoS) condition. The root cause is improper validation of user input in incoming HTTP packets. An attacker would need valid Administrator credentials to exploit this flaw, which they could do by sending a specially crafted HTTP request to the affected device's management interface. Successful exploitation could result in the router being reloaded, causing a disruption in service.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Rv320 Firmware
  • Cisco Rv325 Firmware

Affected Vendors

  • Cisco