Security
Headlines
HeadlinesLatestCVEs

Headline

Cisco router flaw gives patient attackers full access to small business networks

Vulnerable path is reachable just once a day, but patches still need to be implemented as a matter of priority

PortSwigger
#vulnerability#web#microsoft#cisco#rce#auth

James Walker 10 August 2022 at 12:52 UTC

Vulnerable path is reachable just once a day, but patches still need to be implemented as a matter of priority

A high-impact vulnerability in small business routers from Cisco could allow “patient and suitably positioned attackers” to obtain unauthenticated remote code execution on affected devices.

The flaw was discovered by researchers at Onekey (formerly IoT Inspector), who found that improper input validation in the Cisco RV160, RV260, RV340, and RV345 series of routers could allow a remote attacker to execute arbitrary commands on the system.

“By sending a specially-crafted input to the web filter database update feature, an attacker could exploit this vulnerability to execute arbitrary commands on the underlying operating system with root privileges,” the team said in a technical blog post this week.

Perfect timing

Tracked as CVE-2022-20827 and with a CVSS score of 9.0, the Cisco router vulnerability relates to a flaw in the BrightCloud web filtering feature that comes bundled with the devices.

The researchers discovered the vulnerability when hunting for bugs to craft exploit chains for the Pwn2Own 2021 live hacking event.

RELATED Vulnerability in DrayTek routers leaves thousands of SMEs open to exploitation

“Sadly, the vulnerable path is only reachable once a day, so it did not match the Pwn2Own rules,” they said.

Despite the timing constraints, Onekey said businesses should still implement the fixes as soon as possible. “We know real world attackers can be patient and won’t hesitate to wait on you, so patch your routers,” they said.

Bug ‘dependency’ confusion

In an accompanying security advisory, Cisco released a list of vulnerable router firmware versions and relevant patch guidance.

Incidentally, the advisory states that CVE-222-20827 is “dependent” on another flaw, CVE-2022-20841.

Read more of the latest infosec research news

However, despite noting similarities in the exploits, Onekey researcher Quentin Kaiser told The Daily Swig that one CVE was not reliant on the other.

“I don’t see the ‘dependency’ between those two vulnerabilities,” Kaiser said. “They’re similar in that they’re both exploiting a lack of protection against man-in-the-middle attacks, but they target different components.”

We have asked Cisco for clarification on this point. This article will be updated if we hear back.

RECOMMENDED Microsoft Edge deepens defenses against malicious websites with enhanced security mod

Related news

CVE-2022-38108: Published | Zero Day Initiative

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVE-2022-36957: Published | Zero Day Initiative

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVE-2022-20841: Cisco Security Advisory: Cisco Small Business RV Series Routers Vulnerabilities

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-20841: Cisco Security Advisory: Cisco Small Business RV Series Routers Vulnerabilities

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Patch now! Cisco VPN routers are vulnerable to remote control

Cisco has released a security advisory about some serious security vulnerabilities in multiple Cisco small business VPN routers. The post Patch now! Cisco VPN routers are vulnerable to remote control appeared first on Malwarebytes Labs.

Patch now! Cisco VPN routers are vulnerable to remote control

Cisco has released a security advisory about some serious security vulnerabilities in multiple Cisco small business VPN routers. The post Patch now! Cisco VPN routers are vulnerable to remote control appeared first on Malwarebytes Labs.

Patch now! Cisco VPN routers are vulnerable to remote control

Categories: Exploits and vulnerabilities Categories: News Tags: Cisco Tags: VPN routers Tags: CVE-2022-20842 Tags: CVE-2022-20827 Tags: CVE-2022-20841 Tags: input validation Cisco has released a security advisory about some serious security vulnerabilities in multiple Cisco small business VPN routers. (Read more...) The post Patch now! Cisco VPN routers are vulnerable to remote control appeared first on Malwarebytes Labs.

Patch now! Cisco VPN routers are vulnerable to remote control

Categories: Exploits and vulnerabilities Categories: News Tags: Cisco Tags: VPN routers Tags: CVE-2022-20842 Tags: CVE-2022-20827 Tags: CVE-2022-20841 Tags: input validation Cisco has released a security advisory about some serious security vulnerabilities in multiple Cisco small business VPN routers. (Read more...) The post Patch now! Cisco VPN routers are vulnerable to remote control appeared first on Malwarebytes Labs.

Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws

Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution (RCE) or cause a denial-of-service (DoS) condition on affected devices. The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers. Tracked as CVE-2022-20842 (CVSS score: 9.8)

Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws

Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution (RCE) or cause a denial-of-service (DoS) condition on affected devices. The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers. Tracked as CVE-2022-20842 (CVSS score: 9.8)

PortSwigger: Latest News

We’re going teetotal: It’s goodbye to The Daily Swig