← Back
CVE-2022-20759
high
CVSS 8.8
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authen...
Summary
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is...
AI summary openai / gpt-4o
Cisco ASAおよびFTDソフトウェアのリモートアクセスVPN機能における脆弱性を利用して、認証された攻撃者が特権をレベル15に強化する可能性があります。この脆弱性は、認証および認可スコープの不適切な分離によるもので、細工されたHTTPSメッセージを介して悪用されます。
❓ What is the problem
Cisco ASAおよびFTDのVPN機能における特権の昇格問題です。
📍 Affected scope
Cisco Adaptive Security Appliance (ASA) SoftwareとCisco Firepower Threat Defense (FTD) SoftwareのWebサービスインターフェース。
🔥 Severity
攻撃者がレベル15の特権を獲得可能で、重大な影響を及ぼします。
🔧 How to fix
Ciscoによる公式パッチを適用します。
🛡️ Workaround
公式のパッチが適用可能になるまでアクセス制限を強化する。
🔍 Detection
Ciscoの管理ツールを用いて特権レベルの設定を確認する。