cisco-sa-openssl-W9sdCc2a
Vulnerabilities in OpenSSL Affecting Cisco Products: November 2022
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
Vulnerabilities in OpenSSL Affecting Cisco Products: November 2022
Cisco Identity Services Engine Unauthorized File Access Vulnerability
CVEs:CVE-2022-20822
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-111903 | affected | Cisco | — | — |
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
CVEs:CVE-2022-20959
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-111903 | affected | Cisco | — | — |
Cisco Meraki MX and Z3 Teleworker Gateway VPN Denial of Service Vulnerability
CVEs:CVE-2022-20933
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-204724 | affected | Cisco | — | — |
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
CVEs:CVE-2022-20811CVE-2022-20776CVE-2022-20953CVE-2022-20954CVE-2022-20955
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-265966 | affected | Cisco | — | — |
| CVRFPID-278404 | affected | Cisco | — | — |
Cisco Touch 10 Devices Downgrade Vulnerability
CVEs:CVE-2022-20931
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-278404 | affected | Cisco | — | — |
Cisco Touch 10 Devices Insufficient Identity Verification Vulnerability
CVEs:CVE-2022-20793
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-265966 | affected | Cisco | — | — |
| CVRFPID-278404 | affected | Cisco | — | — |
Cisco Enterprise NFV Infrastructure Software Improper Signature Verification Vulnerability
CVEs:CVE-2022-20929
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-235874 | affected | Cisco | — | — |
Cisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVEs:CVE-2022-20686CVE-2022-20687CVE-2022-20688CVE-2022-20689CVE-2022-20690CVE-2022-20691CVE-2022-20766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-2057 | affected | Cisco | — | — |
| CVRFPID-278991 | affected | Cisco | — | — |
Cisco BroadWorks Hosted Thin Receptionist Cross-Site Scripting Vulnerability
CVEs:CVE-2022-20948
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-282087 | affected | Cisco | — | — |
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVEs:CVE-2022-20939
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-274027 | affected | Cisco | — | — |
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
CVEs:CVE-2022-20814CVE-2022-20853
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-209614 | affected | Cisco | — | — |
Cisco Jabber Client Software Extensible Messaging and Presence Protocol Stanza Smuggling Vulnerability
CVEs:CVE-2022-20917
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-278016 | affected | Cisco | — | — |
Cisco Secure Web Appliance Content Encoding Filter Bypass Vulnerabilities
CVEs:CVE-2023-20099CVE-2022-20952
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.