Use of Hard-coded Cryptographic Key in Cisco AsyncOS for Secure Web Appliance and Cisco AsyncOS for Cisco Email Security Appliance - CVE-2022-20868

 

Use of Hard-coded Cryptographic Key in Cisco AsyncOS for Secure Web Appliance and Cisco AsyncOS for Cisco Email Security Appliance - CVE-2022-20868

Published: November 3, 2022


Vulnerability identifier: #VU68966
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20868
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the device.

The vulnerability exists due to usage of a hard-coded value to encrypt a token that is used for certain API calls. A remote user can send a specially crafted HTTP request to the next-generation UI management interface, impersonate another valid user and execute commands with the privileges of that user account.


Affected software

Cisco AsyncOS for Secure Web Appliance
Cisco AsyncOS for Cisco Email Security Appliance

How to mitigate CVE-2022-20868

Install updates from vendor's website.

Cisco AsyncOS for Secure Web Appliance - addressed in versions 14.2.0-217, 14.3.0-115
Cisco AsyncOS for Cisco Email Security Appliance - addressed in versions 14.2.1-015, 14.3.0-020

External References

Related Security Bulletins