CVE-2020-3276
Description
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands on an affected device. The vulnerabilities exist because the web-based management interface does not properly validate user-supplied input to scripts. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending malicious requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Cisco Small Business RV Series Routers Command Injection Vulnerabilities For Cisco Application Extension Platform | NCM |
| Cisco Small Business RV Series Routers Command Injection Vulnerabilities For Cisco Small Business RV Series Routers | NCM |
| Cisco Small Business RV Series Routers Command Injection Vulnerabilities For Cisco IOS XR Software | NCM |
| Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability (CVE-2020-3276) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1705914 | Security Update for Cisco Application Extension Platform 1.0.3.16 |
| PATCH-1705925 | Security Update for Cisco Small Business RV Series Routers 1.0.3.16 |
| PATCH-1705733 | Security Update for Cisco IOS XR Software 4.0.3.8-tm |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234