Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: Cisco urges customers to patch vulnerabilities discovered in its RV series routers.
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Cisco urges customers to patch vulnerabilities discovered in its RV series routers.
IT Security

Cisco urges customers to patch vulnerabilities discovered in its RV series routers.

Editorial Desk
Last updated: August 8, 2022 6:43 pm
Editorial Desk
Share
SHARE

Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers are vulnerable to three vulnerabilities, according to the company.

An unauthenticated remote attacker may execute arbitrary code or cause a denial of service (DoS) condition on a vulnerable device.

CISA issued its own warning about the vulnerabilities on Thursday, saying they may allow someone to seize control of a vulnerable system.

Two of the bugs — labeled CVE-2022-20827 and CVE-2022-20841 — affect nine router models, while CVE-2022-20842 affects four.

‘In addition, a software release that is affected by one vulnerability may not be affected by the other vulnerabilities,’ Cisco said.

CVE-2022-20842 and CVE-2022-20827 are rated “critical” and carry vulnerability scores (CVSS) of 9.8 and 9, respectively.

CVE-2022-20841 is rated “high” and has a CVSS of 8.3.

Cisco says these vulnerabilities are dependent on one another because exploiting one may be necessary to exploit the others.

“Affected software releases may not be affected by the other vulnerabilities,” Cisco adds.

Cisco’s security team says they are not aware of any malicious use of the vulnerabilities, and there are no workarounds to address them.

Chris Clements, VP of solutions architecture at Cerberus Sentinel, believes the most severe issues that can be exploited by an unauthenticated remote attacker are those that target Cisco devices’ web management interface.

According to Clements, Shodan, a search engine for internet-connected devices, found over 12,000 web management interfaces exposed to the internet, with most based in the U.S.

“An attacker exploiting a gateway device can pose a substantial risk to an organisation, particularly if internal or external IT providers have enabled remote management of the devices without appreciating the security risks, which may have caused the devices to have internet access to the management interface,”

“It is clear from this data that devices have either been erroneously configured to provide internet access to the management interface or, more likely, deliberately by an external or internal IT supplier to enable remote management of the devices,” says Clements

Cisco’s patches in 2022 also addressed issues in the web-based management interface allowing an attacker to escalate privileges to root and execute arbitrary commands on the devices

Roger Grimes, VP of KnowBe4, says that although Cisco vulnerabilities are significant, most Cisco devices have unpatched vulnerabilities.

“In my 20-year career of penetration testing, I never found a fully patched Cisco router. This is just one more Cisco router exploit that attackers can use. However, attackers who target Cisco routers will likely score a bull’s eye.” says Grimes.

By Editorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article Quasar uses Microsoft Azure Quasar Delivers Space Data As A Service
Next Article Tech Jobs Australia 1M Australia To Create Over 1 Million Tech Jobs by 2030
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Cisco RV router patch

Tech Articles

Healthcare AI

AI Is Transforming Healthcare By Improving Workflows And Resource Management

Artificial Intelligence (AI) is transforming every industry. In healthcare, there…

October 12, 2024
Influence Of Artificial Intelligence (AI) On Humanity

The Rising Influence Of Artificial Intelligence (AI) On Humanity And Identity

Humanity in Transition: The Rising Influence of Artificial Intelligence on…

November 8, 2024
VPN Service Providers Cyber Attacks

Should VPN Service Providers Be Held Accountable For Cyber Attacks?

Should VPN service providers be held accountable for cyber attacks…

November 3, 2024

Recent News

Forescout Acquire Cysiv
IT Security

Forescout Announces Intent to Acquire Cysiv

4 Min Read
apple
IT Security

Apple rolls out emergency updates to address zero-day exploits

3 Min Read
Wordfence Download Manager Patched
IT Security

High Severity Vulnerability Patched in WordPress Download Manager Plugin

6 Min Read
Microsoft addresses 59 CVEs including critical zero-day flaws
IT Security

Microsoft’s Latest Patch Addresses 59 CVEs And Critical Zero-Day Flaws

3 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

December, 10, 2024

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2024

Welcome Back!

Sign in to your account