cbcvebase.
CVE-2022-20926
published 2022-11-15

CVE-2022-20926: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.83%
53.6th percentile
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.

Affected

23 ranges
VendorProductVersion rangeFixed in
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscocisco_firepower_management_center
ciscofirepower_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center
ciscosecure_firewall_management_center

Detection & IOCsextracted from sources · hover to see the quote

  • Target API endpoints on Cisco FMC web management interface that accept user-supplied parameters; look for crafted/anomalous input to API endpoints by authenticated users with Devices permissions (Administrator, Security Approver, or Network Admin roles)
  • Monitor for unexpected OS command execution originating from the FMC web management process running under low-privilege system accounts, which may indicate successful exploitation
  • Correlate exploitation attempts with authenticated sessions belonging to users holding Devices permissions; flag API calls from these roles that contain shell metacharacters or injection payloads in parameters
  • Track Cisco Bug IDs CSCwb23029 and CSCwb23048 for vendor patch and indicator updates related to this vulnerability
  • ·Exploitation requires valid authenticated credentials; unauthenticated exploitation is not possible. Scope detection efforts to sessions authenticated as Administrator, Security Approver, or Network Admin roles.
  • ·No workarounds are available; detection must rely on monitoring and patching. Ensure FMC is updated per Cisco's November 2022 advisory bundle.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.