VDB
CVE-2022-20759
CVE-2022-20759
PUBLISHED
Es existiert eine Schwachstelle in Cisco ASA (Adaptive Security Appliance) und Cisco Firepower. Der Fehler besteht aufgrund einer unsachgemäßen Trennung von Authentifizierungs- und Autorisierungsbereichen. Ein entfernter, authentisierter Angreifer kann diese Schwachstelle ausnutzen, um seine Privilegien zu erweitern.
EPSS 13.39% · 94.3th percentile
Risk Scores
EPSS Score
13.39%
94.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Firepower Threat Defense | |
| Cisco | Cisco ASA (Adaptive Security Appliance) |
Exploit Intelligence
- https://github.com/orangecertcc/security-research/security/advisories/GHSA-gq88-gqmj-7v24 (nist-nvd)
- CIRCL seen: CVE-2022-20759 (circl-sighting)
- CIRCL seen: CVE-2022-20759 (circl-sighting)
- 20220427 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability (circl)
Timeline
- Apr 27, 2022 CVE Published
- May 3, 2022 EPSS Score
- Jun 22, 2022 EPSS Score
- Sep 30, 2022 EPSS Score
- Nov 18, 2022 EPSS Score
- Feb 25, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Jun 4, 2023 EPSS Score
- Jul 24, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 20, 2023 EPSS Score
- Feb 7, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2024-1218.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1218 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-dos-tL4uA4AA advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asafdt-webvpn-dos-tzPSYern advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ipsec-mitm-CKnLr4 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-mgmt-privesc-BMFMUvye advisory
- https://inthewild.io/vuln/CVE-2022-20759 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq advisory