CVE-2022-20677
Summary
| CVE | CVE-2022-20677 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-15 15:15:00 UTC |
| Updated | 2023-11-07 03:42:00 UTC |
| Description | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 1100-4g Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-6g Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1101 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1109 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1111x Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 111x Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1120 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1131 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1160 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4221 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 8101-32fh | - | All | All | All |
| Hardware | Cisco | 8101-32h | - | All | All | All |
| Hardware | Cisco | 8102-64h | - | All | All | All |
| Hardware | Cisco | 8201 | - | All | All | All |
| Hardware | Cisco | 8201-32fh | - | All | All | All |
| Hardware | Cisco | 8202 | - | All | All | All |
| Hardware | Cisco | 8800 | - | All | All | All |
| Hardware | Cisco | Asr 1001-x | - | All | All | All |
| Hardware | Cisco | Asr 1002-hx | - | All | All | All |
| Hardware | Cisco | Asr 1006-x | - | All | All | All |
| Hardware | Cisco | Asr 1009-x | - | All | All | All |
| Hardware | Cisco | Asr 900 | - | All | All | All |
| Hardware | Cisco | Asr 9000v-v2 | - | All | All | All |
| Hardware | Cisco | Asr 9001 | - | All | All | All |
| Hardware | Cisco | Asr 9006 | - | All | All | All |
| Hardware | Cisco | Asr 9010 | - | All | All | All |
| Hardware | Cisco | Asr 9901 | - | All | All | All |
| Hardware | Cisco | Asr 9902 | - | All | All | All |
| Hardware | Cisco | Asr 9903 | - | All | All | All |
| Hardware | Cisco | Asr 9904 | - | All | All | All |
| Hardware | Cisco | Asr 9906 | - | All | All | All |
| Hardware | Cisco | Asr 9910 | - | All | All | All |
| Hardware | Cisco | Asr 9912 | - | All | All | All |
| Hardware | Cisco | Asr 9922 | - | All | All | All |
| Hardware | Cisco | Catalyst 3650 | - | All | All | All |
| Hardware | Cisco | Catalyst 3850 | - | All | All | All |
| Hardware | Cisco | Catalyst 8200 | - | All | All | All |
| Hardware | Cisco | Catalyst 8300 | - | All | All | All |
| Hardware | Cisco | Catalyst 8500 | - | All | All | All |
| Hardware | Cisco | Catalyst 8500l | - | All | All | All |
| Hardware | Cisco | Catalyst 9200 | - | All | All | All |
| Hardware | Cisco | Catalyst 9300 | - | All | All | All |
| Hardware | Cisco | Catalyst 9400 | - | All | All | All |
| Hardware | Cisco | Catalyst 9500 | - | All | All | All |
| Hardware | Cisco | Catalyst 9500h | - | All | All | All |
| Hardware | Cisco | Catalyst 9600 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-40 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-80 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-cl | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-l | - | All | All | All |
| Hardware | Cisco | Catalyst Cg418-e | - | All | All | All |
| Hardware | Cisco | Catalyst Cg522-e | - | All | All | All |
| Hardware | Cisco | Catalyst Ess9300 | - | All | All | All |
| Hardware | Cisco | Catalyst Ie3200 | - | All | All | All |
| Hardware | Cisco | Catalyst Ie3300 | - | All | All | All |
| Hardware | Cisco | Catalyst Ie3400 | - | All | All | All |
| Hardware | Cisco | Catalyst Ie9300 | - | All | All | All |
| Hardware | Cisco | Cloud Services Router 1000v | - | All | All | All |
| Hardware | Cisco | Esr3300 | - | All | All | All |
| Hardware | Cisco | Esr6300 | - | All | All | All |
| Operating System | Cisco | Ios | 17.6.1 | All | All | All |
| Hardware | Cisco | Isr 1100-4g | - | All | All | All |
| Hardware | Cisco | Isr 1100-6g | - | All | All | All |
| Hardware | Cisco | Isr 1101 | - | All | All | All |
| Hardware | Cisco | Isr 1109 | - | All | All | All |
| Hardware | Cisco | Isr 1111x | - | All | All | All |
| Hardware | Cisco | Isr 111x | - | All | All | All |
| Hardware | Cisco | Isr 1120 | - | All | All | All |
| Hardware | Cisco | Isr 1131 | - | All | All | All |
| Hardware | Cisco | Isr 1160 | - | All | All | All |
| Hardware | Cisco | Isr 4221 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20220413 Cisco IOx Application Hosting Environment Vulnerabilities | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 317164 Cisco IOx Application Hosting Environment Multiple Vulnerabilities (cisco-sa-iox-yuXQ6hFj)