CVE-2022-20759
published 2022-05-03CVE-2022-20759: A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…
PriorityP273high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
29.22%
98.0th percentile
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device. This includes privilege level 15 access to the device using management tools like the Cisco Adaptive Security Device Manager (ASDM) or the Cisco Security Manager (CSM). Note: With Cisco FTD Software, the impact is lower than the CVSS score suggests because the affected web management interface allows for read access only.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | < 9.12.4.38 | 9.12.4.38 |
| cisco | adaptive_security_appliance_software | >= 9.13.0 < 9.14.4 | 9.14.4 |
| cisco | adaptive_security_appliance_software | >= 9.15.0 < 9.15.1.21 | 9.15.1.21 |
| cisco | adaptive_security_appliance_software | >= 9.16.0 < 9.16.2.14 | 9.16.2.14 |
| cisco | adaptive_security_appliance_software | >= 9.17.0 < 9.17.1.7 | 9.17.1.7 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | firepower_threat_defense | < 6.4.0.15 | 6.4.0.15 |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | >= 6.5.0 < 6.6.5.2 | 6.6.5.2 |
| cisco | firepower_threat_defense | >= 6.7.0 < 7.0.2 | 7.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted HTTPS messages sent to the web services interface of Cisco ASA/FTD devices targeting privilege escalation to level 15 ↗
- →Monitor for unexpected privilege level 15 access to the web management interface (ASDM or CSM) by accounts that are not normally privileged ↗
- →Focus detection on the remote access VPN web services interface; authenticated but low-privileged sessions that suddenly obtain elevated authorization are indicative of exploitation ↗
- ·On Cisco FTD Software, the exploitable web management interface provides read access only, so the practical impact is lower than the CVSS score indicates; prioritize ASA deployments for urgent patching ↗
- ·There are no workarounds available; the only remediation is applying the vendor-supplied software update (tracked as Bug ID CSCvz92016) ↗
- ·The vulnerability requires the attacker to already be authenticated (but unprivileged) to the remote access VPN web services interface before privilege escalation is possible ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
vendor_cisco·2022-04-27·CVSS 8.8
CVE-2022-20759 [HIGH] CWE-266 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15.
This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device. This includes privilege level
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20759 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
CVE-2022-20759: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device. This includes p
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/orangecertcc/security-research/security/advisories/GHSA-gq88-gqmj-7v24https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-mgmt-privesc-BMFMUvyehttps://github.com/orangecertcc/security-research/security/advisories/GHSA-gq88-gqmj-7v24https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-mgmt-privesc-BMFMUvye
2022-05-03
Published