Incorrect Privilege Assignment in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20759
Published: April 27, 2022
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper separation of authentication and authorization scopes in the web services interface for remote access VPN feature. A remote authenticated user can send specially crafted HTTP requests to gain privilege level 15 access to the web management interface of the device
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2022-20759
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.43, 9.12.4.38, 9.14.4, 9.15.1.21, 9.16.2.13, 9.17.1.7