Security News > 2021 > August > Cisco Patches Critical Vulnerability in Small Business VPN Routers

Cisco Patches Critical Vulnerability in Small Business VPN Routers
2021-08-05 13:40

Cisco on Wednesday announced the release of patches for a critical vulnerability in small business VPN routers that could allow unauthenticated attackers to execute arbitrary code on affected devices.

To exploit the bug, a remote, unauthenticated attacker has to send specially crafted HTTP requests to an affected device, which could allow them to execute arbitrary code or cause a denial of service condition.

CVE-2021-1610, a second vulnerability addressed in the same devices, could result in an attacker executing arbitrary commands as root.

While exploitation is similar to the critical vulnerability, authentication is required for a successful attack, which lowers the bug's severity rating to high.

The company has released patches for both issues and says that it's not aware of any malicious attacks exploiting them.

"Organizations that use these Cisco Small Business VPN routers and have exposed their management interface externally can address these flaws by patching their devices. If patching is not feasible at this time, disabling the remote management option on these devices will mitigate the flaws until patches can be applied," Narang said.


News URL

http://feedproxy.google.com/~r/securityweek/~3/8qO3d62csrg/cisco-patches-critical-vulnerability-small-business-vpn-routers

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-08-04 CVE-2021-1610 Unspecified vulnerability in Cisco Small Business RV Series Router Firmware
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about these vulnerabilities, see the Details section of this advisory.
network
low complexity
cisco
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4442 231 3052 1816 604 5703