CVE-2022-20868
published 2022-11-04CVE-2022-20868: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.70%
48.9th percentile
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability.
This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | >= 11.8 < 12.5.5 | 12.5.5 |
| cisco | asyncos | >= 12.0 < 14.2.0 | 14.2.0 |
| cisco | asyncos | >= 13.0 < 14.2.1 | 14.2.1 |
| cisco | asyncos | >= 14.0 < 14.0.4 | 14.0.4 |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24wm-cqx7-gv2j: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appli
ghsa_unreviewed·2022-11-04
CVE-2022-20868 [HIGH] CWE-321 GHSA-24wm-cqx7-gv2j: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appli
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.
Cisco
Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
vendor_cisco·2022-11-02·CVSS 5.4
CVE-2022-20867 [MEDIUM] CWE-321 Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
Multiple vulnerabilities in the next-generation UI management interface for Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an attacker to elevate privileges or to conduct a SQL injection attack and obtain root privileges.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/secu
Cisco
Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20868 Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
CVE-2022-20868: Cisco Email Security Appliance, Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance Next Generation Management Vulnerabilities
Multiple vulnerabilities in the next-generation UI management interface for Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an attacker to elevate privileges or to conduct a SQL injection attack and obtain root privileges. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-321, CWE-89, CWE-321, CWE-89
Bug IDs: CSCwc12181, CSCwc12183, CSCwc12184, CSCwc12181, CSCwc12183
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-04
Published