Vulnerability identifier: #VU69205
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20949
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to improper management of internal resources within the application in the management web server. A remote administrator can send specially crafted messages to the affected HTTPS handler and perform configuration changes on the affected system.
Affected software
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2022-20949
Install updates from vendor's website.
Cisco Firewall Threat Defense (FTD) - addressed in versions 006.006(007), 007.000(004), 007.002(001), 009.008(004.046), 009.012(004.051), 9.12.4.52, 9.14.4.13, 009.014(004.013), 9.14.4.14, 009.016(003.016), 9.16.3.19, 9.16.3.23, 009.016(003.099), 009.016(004), 009.017(001.017), 009.018(001.099), 009.018(002), 9.18.2, 009.019(000.099), 099.014(004.027), 099.017(002.139), 099.018(002.032), 099.019(001.129), 099.019(021.038), 099.019(022.035), 099.020(000.006)
External References
Related Security Bulletins