7.8
CVSSv2

CVE-2020-3358

Published: 16/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote malicious user to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to the targeted device. A successful exploit could allow the malicious user to cause a reload, resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco rv340_dual_wan_gigabit_vpn_router_firmware

cisco rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware

cisco rv345_dual_wan_gigabit_vpn_router_firmware

cisco rv345p_dual_wan_gigabit_poe_vpn_router_firmware

Vendor Advisories

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition The vulnerability is due to a lack of proper input validation of HTTP requests An attacker could exploit this ...

Recent Articles

Finally done with all those Patch Tuesday updates? Think again! Here's 33 Cisco bug fixes, with five criticals
The Register • Shaun Nichols in San Francisco • 16 Jul 2020

And who's that in the background? Just Oracle and its *cough* 443 bugs

Cisco has emitted 33 security bug fixes in its latest crop of software updates, five of those deemed critical. Those five critical vulnerabilities include two remote code execution bugs (CVE-2020-3323, CVE-2020-3321) – with no workarounds for either other than patching – and one each of authentication bypass (CVE-2020-3144), privilege escalation (CVE-2020-3140), and default credential (CVE-2020-3330) flaws. Affected devices include multiple RV-series routers, the RV110W series VPN Firewall, ...