CVE-2022-20926
published 2022-11-15CVE-2022-20926: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.83%
53.6th percentile
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | cisco_firepower_management_center | — | — |
| cisco | firepower_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
| cisco | secure_firewall_management_center | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target API endpoints on Cisco FMC web management interface that accept user-supplied parameters; look for crafted/anomalous input to API endpoints by authenticated users with Devices permissions (Administrator, Security Approver, or Network Admin roles) ↗
- →Monitor for unexpected OS command execution originating from the FMC web management process running under low-privilege system accounts, which may indicate successful exploitation ↗
- →Correlate exploitation attempts with authenticated sessions belonging to users holding Devices permissions; flag API calls from these roles that contain shell metacharacters or injection payloads in parameters ↗
- →Track Cisco Bug IDs CSCwb23029 and CSCwb23048 for vendor patch and indicator updates related to this vulnerability ↗
- ·Exploitation requires valid authenticated credentials; unauthenticated exploitation is not possible. Scope detection efforts to sessions authenticated as Administrator, Security Approver, or Network Admin roles. ↗
- ·No workarounds are available; detection must rely on monitoring and patching. Ensure FMC is updated per Cisco's November 2022 advisory bundle. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Firepower Management Center Software Command Injection Vulnerabilities
vendor_cisco·2022-11-09·CVSS 6.3
CVE-2022-20925 [MEDIUM] CWE-77 Cisco Firepower Management Center Software Command Injection Vulnerabilities
Cisco Firepower Management Center Software Command Injection Vulnerabilities
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
These vulnerabilities are due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit these vulnerabilities by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit these vulnerabilities, an attacker would need valid credentials for a user who has Devices permissions. By default, only Administrator, Security A
Cisco
Cisco Firepower Management Center Software Command Injection Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20926 Cisco Firepower Management Center Software Command Injection Vulnerabilities
CVE-2022-20926: Cisco Firepower Management Center Software Command Injection Vulnerabilities
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. These vulnerabilities are due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit these vulnerabilities by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit these vulnerabilities, an attacker would need valid credentials for a user who has Devices permissions. By default, only Administra
GHSA
GHSA-3vp5-85fp-rw6x: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker
ghsa_unreviewed·2022-11-16
CVE-2022-20926 [HIGH] CWE-77 GHSA-3vp5-85fp-rw6x: A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-15
Published