CVE-2022-20925Command Injection in Cisco Firepower Management Center

Severity
7.2HIGHNVD
CNA6.3
EPSS
0.4%
top 39.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateNov 16

Description

A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cw3q-4545-8g5x: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker2022-11-16
CVEList
CVE-2022-20925: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker2022-11-10

📋Vendor Advisories

1
Cisco
Cisco Firepower Management Center Software Command Injection Vulnerabilities2022-11-09
CVE-2022-20925 — Command Injection in Cisco | cvebase