Cisco Security Advisories · July 2022 — Cisco Security Advisories
16 advisories 55 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2022-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-cucm-imp-afr-YBFLNyzd

Cisco PSIRTPoC exploitHIGH2022-07-06

Cisco Unified Communications Products Arbitrary File Read Vulnerability

CVEs:CVE-2022-20791

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-277610 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-ucm-timing-JVbHECOK

Cisco PSIRTPoC exploitHIGH2022-07-06

Cisco Unified Communications Products Timing Attack Vulnerability

CVEs:CVE-2022-20752

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-277610 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-cucm-xss-RgH7MpKA

Cisco PSIRTPoC exploitHIGH2022-07-06

Cisco Unified Communications Products Cross-Site Scripting Vulnerability

CVEs:CVE-2022-20800

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-277610 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-sb-rv-rce-overflow-ygHByAK

Cisco PSIRTCoalition ESS < 30%HIGH2022-07-20

Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerabilities

CVEs:CVE-2022-20873CVE-2022-20874CVE-2022-20875CVE-2022-20876CVE-2022-20881CVE-2022-20877CVE-2022-20878CVE-2022-20879CVE-2022-20880CVE-2022-20882CVE-2022-20883CVE-2022-20884CVE-2022-20885CVE-2022-20886CVE-2022-20887CVE-2022-20888CVE-2022-20889CVE-2022-20890CVE-2022-20891CVE-2022-20892CVE-2022-20893CVE-2022-20894CVE-2022-20895CVE-2022-20896CVE-2022-20897CVE-2022-20898CVE-2022-20899CVE-2022-20900CVE-2022-20901CVE-2022-20902CVE-2022-20903CVE-2022-20904CVE-2022-20910CVE-2022-20911CVE-2022-20912

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
Upstream advisory

cisco-sa-ucm-access-dMKvV2DY

Cisco PSIRTCoalition ESS < 30%HIGH2022-07-06

Cisco Unified Communications Products Access Control Vulnerability

CVEs:CVE-2022-20859

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-277610 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-roomos-infodisc-YOTz9Ct7

Cisco PSIRTCoalition ESS < 30%HIGH2022-07-06

Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

CVEs:CVE-2022-20768

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-265966 affected Cisco
CVRFPID-278404 affected Cisco
Upstream advisory

cisco-sa-cucm-xss-ksKd5yfA

Cisco PSIRTCoalition ESS < 30%HIGH2022-07-06

Cisco Unified Communications Products Cross-Site Scripting Vulnerability

CVEs:CVE-2022-20815

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.