CVE-2022-20759Incorrect Privilege Assignment in Cisco Adaptive Security Appliance Software

Severity
8.8HIGHNVD
EPSS
13.4%
top 5.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3

Description

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected devic

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

1
CVEList
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability2022-05-03

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability2022-04-27
CVE-2022-20759 — Incorrect Privilege Assignment | cvebase