CVE-2022-20926
Published on: Not Yet Published
Last Modified on: 11/22/2022 12:43:00 AM UTC
CVE-2022-20926 - advisory for cisco-sa-fmc-cmd-inj-Z3B5MY35
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Firepower Management Center from Cisco contain the following vulnerability:
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.
- CVE-2022-20926 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
No Description Provided | tools.cisco.com text/html |
![]() |
Related QID Numbers
- 317271 Cisco Firepower Management Center (FMC) Software Command Injection Vulnerabilities (cisco-sa-fmc-cmd-inj-Z3B5MY35)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Firepower Management Center | 7.0.0 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.0.1 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.1 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.1.1 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.2 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.2.1 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.3 | All | All | All |
Application | Cisco | Firepower Management Center | 7.0.4 | All | All | All |
Application | Cisco | Firepower Management Center | 7.1.0 | All | All | All |
Application | Cisco | Firepower Management Center | 7.1.0.1 | All | All | All |
Application | Cisco | Firepower Management Center | 7.1.0.2 | All | All | All |
- cpe:2.3:a:cisco:firepower_management_center:7.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.1.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.2:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.2.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.0.4:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.1.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:firepower_management_center:7.1.0.2:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|