CVE-2022-20952
published 2023-03-01CVE-2022-20952: A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.68%
48.0th percentile
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked.
This vulnerability exists because malformed, encoded traffic is not properly detected. An attacker could exploit this vulnerability by connecting through an affected device to a malicious server and receiving malformed HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | >= 11.8 < 14.0.4 | 14.0.4 |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | cisco_secure_web_appliance | — | — |
| cisco | secure_web_appliance_content_encoding_filter | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-36pr-655q-f5wg: A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA)
ghsa_unreviewed·2023-03-01
CVE-2022-20952 [MEDIUM] CWE-20 GHSA-36pr-655q-f5wg: A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA)
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability exists because malformed, encoded traffic is not properly detected. An attacker could exploit this vulnerability by connecting through an affected device to a malicious server and receiving malformed HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.
Cisco
Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
vendor_cisco·2022-10-05·CVSS 5.3
CVE-2022-20952 [MEDIUM] CWE-20 Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
Multiple vulnerabilities in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked.
These vulnerabilities exist because malformed, encoded traffic is not properly detected. An attacker could exploit these vulnerabilities by connecting through an affected device to a malicious server and receiving malformed HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.
Cisco has released software updates that
Cisco
Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20952 Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
CVE-2022-20952: Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
Multiple vulnerabilities in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. These vulnerabilities exist because malformed, encoded traffic is not properly detected. An attacker could exploit these vulnerabilities by connecting through an affected device to a malicious server and receiving malformed HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device. Cisco has released softwa
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-01
Published