#VU62670 Incorrect Privilege Assignment in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2022-20759

 

#VU62670 Incorrect Privilege Assignment in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2022-20759

Published: April 27, 2022


Vulnerability identifier: #VU62670
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-20759
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper separation of authentication and authorization scopes in the web services interface for remote access VPN feature. A remote authenticated user can send specially crafted HTTP requests to gain privilege level 15 access to the web management interface of the device


Remediation

Install updates from vendor's website.

External links