Use of Hard-coded Cryptographic Key in Cisco AsyncOS for Secure Web Appliance and Cisco AsyncOS for Cisco Email Security Appliance - CVE-2022-20868
Published: November 3, 2022
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the device.
The vulnerability exists due to usage of a hard-coded value to encrypt a token that is used for certain API calls. A remote user can send a specially crafted HTTP request to the next-generation UI management interface, impersonate another valid user and execute commands with the privileges of that user account.
Affected software
Cisco AsyncOS for Cisco Email Security Appliance
How to mitigate CVE-2022-20868
Cisco AsyncOS for Cisco Email Security Appliance - addressed in versions 14.2.1-015, 14.3.0-020