CVE-2024-20523

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 121
CWE ID 787

Summary

CVE-2024-20523 is a vulnerability affecting the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers. This issue permits an authenticated, Administrator-level, remote attacker to induce an unexpected reload of an affected device, leading to a denial of service (DoS) condition. The root cause is insufficient input validation in the handling of HTTP packets. An attacker can exploit this flaw by sending a specially crafted HTTP request to the targeted device's web-based management interface. Successful exploitation results in an unwanted reload, causing a DoS condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Rv320 Firmware
  • Cisco Rv325 Firmware

Affected Vendors

  • Cisco