#VU66597 OS Command Injection in Cisco AsyncOS for Web Security Appliances - CVE-2022-20871
Published: August 17, 2022
Cisco AsyncOS for Web Security Appliances
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the web interface. A remote user can send a specially crafted HTTP request to the affected device and execute arbitrary OS commands with root privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.