VDB

CVE-2022-20826

CVE-2022-20826 PUBLISHED CVSS 6.400000095367432 MEDIUM

A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.

EPSS 0.40% · 61.2th percentile

Risk Scores

CVSS 3.1
6.400000095367432
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.40%
61.2th percentile

Affected Products

VendorProductVersions
ciscoadaptive_security_appliance_software9.18.1.3, 9.17.1.10, 9.17.1.9
CiscoCisco Adaptive Security Appliance (ASA) Software9.18.1.3, 9.17.1.13, 9.18.1
CiscoCisco Firepower Threat Defense Software7.1.0, 7.2.0, 7.2.0.1
ciscofirepower_threat_defense7.2.0.0, 7.2.0.1, 7.1.0.0

Exploit Intelligence

Timeline

  • Nov 10, 2022 CVE Published
  • Nov 16, 2022 EPSS Score
  • Dec 29, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 24, 2023 EPSS Score
  • May 6, 2023 EPSS Score
  • Jun 18, 2023 EPSS Score
  • Jul 31, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
  • Dec 6, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›