← Retour
CVE-2022-20759
high
CVSS 8.8
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authen...
Résumé
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2022-20759** a été découverte dans cisco.
Des attaquants peuvent cibler un point d'entrée spécifique comme `GET /admin/exec/show` à distance pour détourner le produit.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 8.8/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « cisco CVE-2022-20759 » sur le site de l'éditeur.
CVE-2022-20759 (cisco) — CWE-266 / CVSS v3 8.8
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Surface d'attaque : GET /admin/exec/show
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Cisco ASAおよびFTDのVPN機能における特権の昇格問題です。
📍 Périmètre concerné
Cisco Adaptive Security Appliance (ASA) SoftwareとCisco Firepower Threat Defense (FTD) SoftwareのWebサービスインターフェース。
🔥 Gravité
攻撃者がレベル15の特権を獲得可能で、重大な影響を及ぼします。
🔧 Comment corriger
Ciscoによる公式パッチを適用します。
🛡️ Contournement
公式のパッチが適用可能になるまでアクセス制限を強化する。
🔍 Détection
Ciscoの管理ツールを用いて特権レベルの設定を確認する。