Trust Boundary Violation in Cisco Systems, Inc products - CVE-2022-20826
Published: November 10, 2022
Vulnerability identifier: #VU69198
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20826
CWE-ID:
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to a logic error in the boot process. An attacker with physical access can execute persistent code at boot time and break the chain of trust.
Affected software
Secure Firewall 3100
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2022-20826
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 1.0.22, 1.2.17, 7.1.0.2, 7.2.1
Cisco Adaptive Security Appliance (ASA) - addressed in versions 1.0.22, 1.2.17, 9.17.1.15, 9.18.2
Cisco Adaptive Security Appliance (ASA) - addressed in versions 1.0.22, 1.2.17, 9.17.1.15, 9.18.2