Cisco Security Advisories · May 2022 — Cisco Security Advisories
15 advisories 29 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2022-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-clamav-dos-prVGcHLd

Cisco PSIRTCoalition ESS < 30%HIGH2022-05-04

ClamAV CHM File Parsing Denial of Service Vulnerability Affecting Cisco Products: May 2022

CVEs:CVE-2022-20770

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-221075 affected Cisco
Upstream advisory

cisco-sa-clamav-dos-ZAZBwRVG

Cisco PSIRTCoalition ESS < 30%HIGH2022-05-04

ClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: May 2022

CVEs:CVE-2022-20771

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-221075 affected Cisco
Upstream advisory

cisco-sa-stealth-rce-2hYb9KFK

Cisco PSIRTCoalition ESS < 30%HIGH2022-05-18

Cisco Secure Network Analytics Remote Code Execution Vulnerability

CVEs:CVE-2022-20797

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-245631 affected Cisco
CVRFPID-285963 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.