Cisco VPN Routers Remote Code Execution Vulnerability
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
- Vendor
- Cisco
- Product
- VPN Routers
- CVSS
- 9.8
- EPSS (exploit probability)
- 55.2%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
Added to CISA’s Known Exploited Vulnerabilities catalog on 2022-03-25. Required action per CISA: Apply updates per vendor instructions. Due date: 2022-04-15.
This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.