XML injection in Cisco Firewall Threat Defense (FTD) - CVE-2022-20729

 

XML injection in Cisco Firewall Threat Defense (FTD) - CVE-2022-20729

Published: April 28, 2022


Vulnerability identifier: #VU62681
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20729
CWE-ID: CWE-91
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system

The vulnerability exists due to improper input validation when processing XML data in CLI. A local user can pass specially crafted XML data to the application, resulting in unexpected processing of the command and unexpected command output.


Affected software

Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2022-20729

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.15, 6.6.5.2, 7.0.2

External References

Related Security Bulletins