CVE-2022-20871
published 2024-11-15CVE-2022-20871: A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an…
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.86%
76.9th percentile
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.Attention: Simplifying the Cisco portfolio includes the renaming of security products under one brand: Cisco Secure. For more information, see .
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | secure_web_appliance | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit requires an authenticated attacker to send a crafted HTTP packet to the web management interface; monitor for anomalous or malformed HTTP requests from authenticated (including read-only) users targeting the Cisco Secure Web Appliance (AsyncOS) management interface. ↗
- →The vulnerability is rooted in insufficient input validation on the web interface (CWE-78 OS Command Injection); focus detection on HTTP request parameters to the management UI that contain shell metacharacters or command-injection payloads. ↗
- →Privilege escalation to root is the end goal; alert on unexpected root-level process spawning from the AsyncOS web management process (e.g., GUI/web worker processes spawning shells). ↗
- →Read-only credentials are sufficient for exploitation; treat any read-only authenticated session making unusual POST/GET requests to the management interface as a potential exploitation attempt. ↗
- ·This is an authenticated vulnerability — unauthenticated access is not sufficient. Ensure management interface access is restricted to trusted networks and that read-only accounts are audited, as they are sufficient for exploitation. ↗
- ·No workarounds exist; patching via Cisco software updates is the only remediation. Track Cisco Bug ID CSCwb92675 for patch status. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Web Appliance Privilege Escalation Vulnerability
vendor_cisco·2022-08-17·CVSS 6.3
CVE-2022-20871 [MEDIUM] CWE-78 Cisco Secure Web Appliance Privilege Escalation Vulnerability
Cisco Secure Web Appliance Privilege Escalation Vulnerability
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.
Cisco has
Cisco
Cisco Secure Web Appliance Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20871 Cisco Secure Web Appliance Privilege Escalation Vulnerability
CVE-2022-20871: Cisco Secure Web Appliance Privilege Escalation Vulnerability
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credenti
GHSA
GHSA-rw66-6rgj-mwjh: A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could al
ghsa_unreviewed·2024-11-15
CVE-2022-20871 [MEDIUM] CWE-78 GHSA-rw66-6rgj-mwjh: A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could al
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.Cisco has released software updates that address this vulnerability. There
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecUhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dvhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8
2024-11-15
Published