CVE-2023-20143 describes multiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of several Cisco Small Business RV series routers (RV016, RV042, RV042G, RV082, RV320, and RV325). These vulnerabilities stem from insufficient input validation, allowing an unauthenticated, remote attacker to inject malicious script code. With a CVSS score of 6.1 (Medium), a successful exploit could lead to arbitrary script execution in the user's browser context or access to sensitive browser-based information, requiring user interaction (UI:R) for exploitation. There is currently no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage. Cisco has not released software updates to address these vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv016_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv042_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv042g_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv082_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv320_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.