Incorrect Privilege Assignment in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20759

 

Incorrect Privilege Assignment in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20759

Published: April 27, 2022


Vulnerability identifier: #VU62670
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20759
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper separation of authentication and authorization scopes in the web services interface for remote access VPN feature. A remote authenticated user can send specially crafted HTTP requests to gain privilege level 15 access to the web management interface of the device


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2022-20759

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.15, 6.6.5.2, 6.7.0.4, 7.0.2, 7.1.0.1
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.43, 9.12.4.38, 9.14.4, 9.15.1.21, 9.16.2.13, 9.17.1.7

External References

Related Security Bulletins