Cisco Small Business Routers Multiple Vulnerabilities (cisco-sa-sbr042-multi-vuln-ej76Pke5)

critical Nessus Plugin ID 173431

Synopsis

The remote device is out of support and affected by multiple vulnerabilities.

Description

According to it's reported model number, the remote device is a Cisco Small Business Router model RV016, RV042, RV042G, RV082, RV320, or RV325. It is, therefore no longer supported and affected by multiple vulnerabilities:

- A vulnerability in the web-based management interface of Cisco Small Business Routers could allow an unauthenticated, remote attacker to bypass authentication on the affected device. This vulnerability is due to incorrect user input validation of incoming HTTP packets. An attacker could exploit this vulnerability by sending crafted requests to the web-based management interface. A successful exploit could allow the attacker to gain root privileges on the affected device. (CVE-2023-20025)

- A vulnerability in the web-based management interface of Cisco Small Business Routers could allow an authenticated, remote attacker to inject arbitrary commands on an affected device. This vulnerability is due to improper validation of user input fields within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. (CVE-2023-20118, CVE-2023-20026)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwd47551, CSCwd60199, CSCwe41652

See Also

http://www.nessus.org/u?dee33f02

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd47551

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd60199

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe41652

Plugin Details

Severity: Critical

ID: 173431

File Name: cisco-sa-sbr042-multi-vuln-ej76Pke5.nasl

Version: 1.1

Type: remote

Family: CISCO

Published: 3/27/2023

Updated: 3/28/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-20025

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/o:cisco:small_business_rv_series_router_firmware, cpe:/o:cisco:rv016_firmware, cpe:/o:cisco:rv042_firmware, cpe:/o:cisco:rv042g_firmware, cpe:/o:cisco:rv082_firmware, cpe:/o:cisco:rv320_firmware, cpe:/o:cisco:rv325_firmware, cpe:/h:cisco:rv016, x-cpe:/h:cisco:rv042, x-cpe:/h:cisco:rv042g, x-cpe:/h:cisco:rv082, x-cpe:/h:cisco:rv320, x-cpe:/h:cisco:rv325

Required KB Items: Cisco/Small_Business_Router/Version, Cisco/Small_Business_Router/Model

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/20/2023

Reference Information

CVE: CVE-2023-20025, CVE-2023-20026, CVE-2023-20118