Observable discrepancy in Cisco Systems, Inc products - CVE-2022-20866
Published: August 11, 2022 / Updated: August 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. A remote attacker can perform a Lenstra side-channel attack and retrieve the RSA private key.
Affected software
ASA 5506H-X with FirePOWER Services
ASA 5506W-X with FirePOWER Services
ASA 5508-X with FirePOWER Services
ASA 5516-X with FirePOWER Services
Firepower 1000 Series Next-Generation Firewall
Firepower 2100 Series Security Appliances
Firepower 4100 Series Security Appliances
Firepower 9300 Series Security Appliances
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Secure Firewall 3100
How to mitigate CVE-2022-20866
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.3.19, 9.17.1.13, 9.18.2