XML injection in Cisco Firewall Threat Defense (FTD) - CVE-2022-20729
Published: April 28, 2022
Vulnerability identifier: #VU62681
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20729
CWE-ID: CWE-91
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system
The vulnerability exists due to improper input validation when processing XML data in CLI. A local user can pass specially crafted XML data to the application, resulting in unexpected processing of the command and unexpected command output.
Affected software
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2022-20729
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.15, 6.6.5.2, 7.0.2