CVE-2024-20517

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 122
CWE ID 787

Summary

CVE-2024-20517 is a vulnerability affecting the web-based management interfaces of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue allows authenticated, Administrator-level attackers to cause an unexpected reload of the device, leading to a denial of service (DoS) condition. The root cause is improper validation of user input in incoming HTTP packets. An attacker would need valid Administrator credentials to exploit this vulnerability and send a crafted HTTP request to the router's web interface, potentially causing the device to reload unexpectedly and become unavailable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Rv320 Firmware
  • Cisco Rv325 Firmware

Affected Vendors

  • Cisco