← Back

CVE-2022-20871

nvd nist
Published: Nov 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see .

Affected (11)

Products: Cisco: Asyncos
1 product
Asyncos
Configuration A
11 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 12.5.1-011
Version 12.5.2-007
Version 12.5.2-011
Version 12.5.3-002
Version 12.5.4-005
Version 12.5.4-011
Version 14.0.2-012
Version 14.1.0-032
Version 14.1.0-041
Version 14.1.0-047
Version 14.5.0-498
Running on/withPlatform Versions
Cisco
Secure Web Appliance S196
All versions
Cisco
Secure Web Appliance S396
All versions
Cisco
Secure Web Appliance S696
All versions
Cisco
Secure Web Appliance Virtual S1000v
All versions
Cisco
Secure Web Appliance Virtual S100v
All versions
Cisco
Secure Web Appliance Virtual S300v
All versions
Cisco
Secure Web Appliance Virtual S600v
All versions

Timeline

No history available yet.