CVE-2024-20516
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-20516 is a vulnerability affecting the web-based management interfaces of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue allows authenticated, Administrator-level, remote attackers to trigger an unexpected reload, leading to a denial of service (DoS) condition. The root cause is improper validation of user input in incoming HTTP packets. An attacker would need valid Administrator credentials to exploit this flaw, which they could do by sending a specially crafted HTTP request to the affected device's management interface. Successful exploitation could result in the router being reloaded, causing a disruption in service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Rv320 Firmware
- Cisco Rv325 Firmware
Affected Vendors
- Cisco