Improper Authentication in Cisco Systems, Inc products - CVE-2022-20798

 

Improper Authentication in Cisco Systems, Inc products - CVE-2022-20798

Published: June 15, 2022


Vulnerability identifier: #VU64421
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20798
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error improper authentication checks when using the Lightweight Directory Access Protocol (LDAP) for external authentication. A remote non-authenticated attacker can bypass specially crafted data to the login page of the affected device, bypass the authenticated process and gain unauthorized access to the system.


Affected software

Secure Email Gateway
Cisco Secure Email and Web Manager
Cisco AsyncOS for Cisco Email Security Appliance
Cisco Email Security Appliance

How to mitigate CVE-2022-20798

Install updates from vendor's website.

Cisco Secure Email and Web Manager - addressed in versions 13.0.0-277, 13.6.2-090, 13.8.1-090, 14.0.0-418, 14.1.0-250
Cisco AsyncOS for Cisco Email Security Appliance - update to 14.0.1-033
Cisco Email Security Appliance - update to 14.0.1-033

External References

Related Security Bulletins