Trust Boundary Violation in Cisco Systems, Inc products - CVE-2022-20826

 

Trust Boundary Violation in Cisco Systems, Inc products - CVE-2022-20826

Published: November 10, 2022


Vulnerability identifier: #VU69198
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20826
CWE-ID:
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to a logic error in the boot process. An attacker with physical access can execute persistent code at boot time and break the chain of trust.


Affected software

Secure Firewall 3100
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2022-20826

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 1.0.22, 1.2.17, 7.1.0.2, 7.2.1
Cisco Adaptive Security Appliance (ASA) - addressed in versions 1.0.22, 1.2.17, 9.17.1.15, 9.18.2

External References

Related Security Bulletins