← Back

CVE-2022-20934

nvd nist
Published: Nov 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.

Affected (156)

2 products
Firepower Threat Defense
Configuration A
24 vulnerable
Configuration B
132 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 1.1.1.147
Version 1.1.1.160
Version 1.1.2.178
Version 1.1.2.51
Version 1.1.3.84
Version 1.1.3.86
Version 1.1.3.97
Version 1.1.4.117
Version 1.1.4.140
Version 1.1.4.169
Version 1.1.4.175
Version 1.1.4.178
Version 1.1.4.179
Version 1.1.4.95
Version 2.0.1.135
Version 2.0.1.141
Version 2.0.1.144
Version 2.0.1.148
Version 2.0.1.149
Version 2.0.1.153
Version 2.0.1.159
Version 2.0.1.188
Version 2.0.1.201
Version 2.0.1.203
Version 2.0.1.204
Version 2.0.1.206
Version 2.0.1.37
Version 2.0.1.68
Version 2.0.1.86
Version 2.1.1.106
Version 2.1.1.107
Version 2.1.1.113
Version 2.1.1.115
Version 2.1.1.116
Version 2.1.1.64
Version 2.1.1.73
Version 2.1.1.77
Version 2.1.1.83
Version 2.1.1.85
Version 2.1.1.86
Version 2.1.1.97
Version 2.10.1.159
Version 2.10.1.166
Version 2.10.1.179
Version 2.11.1.154
Version 2.2.1.63
Version 2.2.1.66
Version 2.2.1.70
Version 2.2.2.101
Version 2.2.2.137
Version 2.2.2.148
Version 2.2.2.149
Version 2.2.2.17
Version 2.2.2.19
Version 2.2.2.24
Version 2.2.2.26
Version 2.2.2.28
Version 2.2.2.54
Version 2.2.2.60
Version 2.2.2.71
Version 2.2.2.83
Version 2.2.2.86
Version 2.2.2.91
Version 2.2.2.97
Version 2.3.1.110
Version 2.3.1.111
Version 2.3.1.130
Version 2.3.1.144
Version 2.3.1.145
Version 2.3.1.155
Version 2.3.1.166
Version 2.3.1.173
Version 2.3.1.179
Version 2.3.1.180
Version 2.3.1.190
Version 2.3.1.215
Version 2.3.1.216
Version 2.3.1.219
Version 2.3.1.56
Version 2.3.1.58
Version 2.3.1.66
Version 2.3.1.73
Version 2.3.1.75
Version 2.3.1.88
Version 2.3.1.91
Version 2.3.1.93
Version 2.3.1.99
Version 2.4.1.101
Version 2.4.1.214
Version 2.4.1.222
Version 2.4.1.234
Version 2.4.1.238
Version 2.4.1.244
Version 2.4.1.249
Version 2.4.1.252
Version 2.4.1.266
Version 2.4.1.268
Version 2.4.1.273
Version 2.6.1.131
Version 2.6.1.157
Version 2.6.1.166
Version 2.6.1.169
Version 2.6.1.174
Version 2.6.1.187
Version 2.6.1.192
Version 2.6.1.204
Version 2.6.1.214
Version 2.6.1.224
Version 2.6.1.229
Version 2.6.1.230
Version 2.6.1.238
Version 2.6.1.239
Version 2.6.1.254
Version 2.7.1.106
Version 2.7.1.122
Version 2.7.1.131
Version 2.7.1.143
Version 2.7.1.92
Version 2.7.1.98
Version 2.8.1.105
Version 2.8.1.125
Version 2.8.1.139
Version 2.8.1.143
Version 2.8.1.152
Version 2.8.1.162
Version 2.8.1.164
Version 2.8.1.172
Version 2.9.1.131
Version 2.9.1.135
Version 2.9.1.143
Version 2.9.1.150
Version 2.9.1.158

Timeline

No history available yet.