CRITICAL · 9.1

CVE-2022-20829

A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authentic...

Vulnerability Description

A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device that is running Cisco ASA Software. This vulnerability is due to insufficient validation of the authenticity of an ASDM image during its installation on a device that is running Cisco ASA Software. An attacker could exploit this vulnerability by installing a crafted ASDM image on the device that is running Cisco ASA Software and then waiting for a targeted user to access that device using ASDM. A successful exploit could allow the attacker to execute arbitrary code on the machine of the targeted user with the privileges of that user on that machine. Notes: To successfully exploit this vulnerability, the attacker must have administrative privileges on the device that is running Cisco ASA Software. Potential targets are limited to users who manage the same device that is running Cisco ASA Software using ASDM. Cisco has released and will release software updates that address this vulnerability.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIsa 3000 Firmware< 9.18.2
CiscoIsa 3000-
CiscoAsa 5585-X Firmware< 9.18.2
CiscoAsa 5585-X-
CiscoAsa 5512-X Firmware< 9.18.2
CiscoAsa 5512-X-
CiscoAsa 5515-X Firmware< 9.18.2
CiscoAsa 5515-X-
CiscoAdaptive Security Device Manager< 7.18.1.150
CiscoFirepower 1010-
CiscoFirepower 1120-
CiscoFirepower 1140-
CiscoFirepower 1150-
CiscoFirepower 2110-
CiscoFirepower 2120-
CiscoFirepower 2130-
CiscoFirepower 2140-
CiscoFirepower 4110-
CiscoFirepower 4112-
CiscoFirepower 4115-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-20829?

CVE-2022-20829 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authentic...

How severe is CVE-2022-20829?

CVE-2022-20829 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-20829?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Isa 3000 Firmware, Cisco Isa 3000, Cisco Asa 5585-X Firmware, Cisco Asa 5585-X, Cisco Asa 5512-X Firmware.