VDB
CVE-2022-20699
CVE-2022-20699
PUBLISHED
KEV
CVSS 9.800000190734863 CRITICAL
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
EPSS 89.40% · 99.6th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
89.40%
99.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Small Business RV Series Router Firmware | * |
| cisco | rv345_firmware | 0, 0 |
| cisco | rv340w_firmware | 0, 0 |
| cisco | rv345p_firmware | 0, 0 |
| cisco | rv340_firmware | 0, 0 |
Exploit Intelligence
- puckiestyle/CVE-2022-20699 (github-poc)
- puckiestyle/CVE-2022-20699 (github-poc)
- puckiestyle/CVE-2022-20699 (github-poc)
- puckiestyle/CVE-2022-20699 (github-poc)
- Cisco Anyconnect VPN unauth RCE (rwx stack) (github-poc)
- Cisco Anyconnect VPN unauth RCE (rwx stack) (github-poc)
- Cisco Anyconnect VPN unauth RCE (rwx stack) (github-poc)
- Cisco Anyconnect VPN unauth RCE (rwx stack) (github-poc)
- http://packetstormsecurity.com/files/167113/Cisco-RV340-SSL-VPN-Unauthenticated-Remote-Code-Execution.html (nist-nvd)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20701 (circl)
…and 16 more exploits
Timeline
- Feb 3, 2022 CVE Published
- Feb 11, 2022 EPSS Score
- Feb 23, 2022 EPSS Score
- Mar 3, 2022 CISA KEV Added
- Apr 4, 2022 EPSS Score
- May 12, 2022 PoC Published
- May 27, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
- Nov 1, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 15, 2023 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-20699 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20699 url
- https://www.zerodayinitiative.com/advisories/ZDI-22-414 url
- http://packetstormsecurity.com/files/167113/Cisco-RV340-SSL-VPN-Unauthenticated-Remote-Code-Execution.html url
- https://www.zerodayinitiative.com/advisories/ZDI-22-414/ advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-412/ url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-20701 url