QID 317217
Date Published: 2022-08-24
QID 317217: Cisco Secure Web Appliance Privilege Escalation Vulnerability (cisco-sa-wsa-prv-esc-8PdRU8t8)
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
Affected Products
Cisco AsyncOS for the Secure Web Appliance, both virtual and hardware appliances.
Version 12.5
Version 14.0
From 14.5 prior to 14.5.0-537
The Qid checks for the Vulnerable version of Cisco WSA and SMA in the response of "version" command.
A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Solution
Customers are advised to refer to cisco-sa-wsa-prv-esc-8PdRU8t8 for more information.
Vendor References
- cisco-sa-wsa-prv-esc-8PdRU8t8 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8
CVEs related to QID 317217
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-wsa-prv-esc-8PdRU8t8 |
|