CVE-2023-20073 is a critical vulnerability affecting the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers. This flaw allows an unauthenticated, remote attacker to upload arbitrary files due to insufficient authorization enforcement during file uploads. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.91399, the vulnerability presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog, exploit code is available via Nuclei templates, and there is significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.03.29CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.29CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.29CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.03.29CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.