A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to the targeted device. A successful exploit could allow the attacker to cause a reload, resulting in a DoS condition.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Rv340 Dual Wan Gigabit Vpn Router
Subscribe
Rv340 Dual Wan Gigabit Vpn Router Firmware
Subscribe
Rv340w Dual Wan Gigabit Wireless-ac Vpn Router
Subscribe
Rv340w Dual Wan Gigabit Wireless-ac Vpn Router Firmware
Subscribe
Rv345 Dual Wan Gigabit Vpn Router
Subscribe
Rv345 Dual Wan Gigabit Vpn Router Firmware
Subscribe
Rv345p Dual Wan Gigabit Poe Vpn Router
Subscribe
Rv345p Dual Wan Gigabit Poe Vpn Router Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24629 | A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request over an SSL connection to the targeted device. A successful exploit could allow the attacker to cause a reload, resulting in a DoS condition. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-15T16:53:59.870Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3358
Updated: 2024-08-04T07:30:58.220Z
Status : Modified
Published: 2020-07-16T18:15:18.173
Modified: 2024-11-21T05:30:52.327
Link: CVE-2020-3358
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD