There will be no fixes or mitigations to handle multiple critical vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers because they are at end of life.

Having said that, these vulnerabilities could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system of an affected device.

Cisco has not released software updates to address the vulnerabilities described in this advisory, according to its advisory. There are no workarounds that address these vulnerabilities.

These vulnerabilities affect all software releases running on the following Cisco RV Series Small Business Routers:

Schneider Bold
  • RV016 Multi-WAN VPN Routers
  • RV042 Dual WAN VPN Routers
  • RV042G Dual Gigabit WAN VPN Routers
  • RV082 Dual WAN VPN Routers

The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit the other vulnerability. In addition, a software release affected by one of the vulnerabilities may not be affected by the other vulnerability.

In one issue, a vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device.

This vulnerability is because of an improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass authentication and gain root access on the underlying operating system.

There are no workarounds that address this vulnerability. However, administrators may disable the affected feature.

CVE-2023-20025 is the case number for the vulnerability, which has a CVSS base score of 9.0.

In addition, there is a vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.

This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device.

CVE-2023-20026 is the case number for the vulnerability, which has a CVSS base score of 6.5.

Administrators can mitigate the vulnerabilities by disabling remote management and blocking access to ports 443 and 60443. The routers will still be accessible through the LAN interface after the mitigation has been implemented.

To disable remote management, do the following:

  1. Log in to the web-based management interface for the device
  2. Choose Firewall > General
  3. Uncheck the Remote Management check box

To block access to Ports 443 and 60443, first, add a new service to the access rules of the device for port 60443. It is not necessary to create a service for port 443 because it is predefined in the services list.

  1. Log in to the web-based management interface for the device
  2. Choose Firewall > Access Rules
  3. Click Service Management
  4. In the Service Name field, enter TCP-60443
  5. From the Protocol drop-down list, choose TCP
  6. In both of the Port Range fields, enter 60443
  7. Click Add to List
  8. Click OK

Next, create access rules to block ports 443 and 60443. To create an access rule to block port 443, do the following:

  1. Log in to the web-based management interface for the device.
  2. Choose Firewall > Access Rules.
  3. Click Add.
  4. From the Action drop-down list, choose Deny.
  5. From the Service drop-down list, choose HTTPS (TCP 443-443).
  6. From the Log drop-down list, choose Log packets match this rule.
  7. From the Source Interface drop-down list, choose the option that matches the WAN connection on the device.
  8. From the Source IP drop-down list, choose Any.
  9. From the Destination IP drop-down list, choose Single.
  10. In both of the Destination IP fields, enter the WAN IP address.
  11. Click Save.

To create an access rule to block port 60443, repeat the preceding steps, but for Step 5, choose HTTPS (TCP 60443-60443) from the Service drop-down list.

If a second WAN port is being used, two additional ACL rules need to be set up using the WAN number and IP address for the second WAN port.

Click here for a complete list of Cisco security fixes.

ISSSource

Pin It on Pinterest

Share This