Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-20677


Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2022-04-15T15:15:12.413

Last Modified

2024-11-21T06:43:17.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 17.6.1 Yes
Hardware cisco 1100-4g_integrated_services_router - No
Hardware cisco 1100-6g_integrated_services_router - No
Hardware cisco 1101_integrated_services_router - No
Hardware cisco 1109_integrated_services_router - No
Hardware cisco 1111x_integrated_services_router - No
Hardware cisco 111x_integrated_services_router - No
Hardware cisco 1120_integrated_services_router - No
Hardware cisco 1131_integrated_services_router - No
Hardware cisco 1160_integrated_services_router - No
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 8101-32fh - No
Hardware cisco 8101-32h - No
Hardware cisco 8102-64h - No
Hardware cisco 8201 - No
Hardware cisco 8201-32fh - No
Hardware cisco 8202 - No
Hardware cisco 8800 - No
Hardware cisco asr_1001-x - No
Hardware cisco asr_1002-hx - No
Hardware cisco asr_1006-x - No
Hardware cisco asr_1009-x - No
Hardware cisco asr_900 - No
Hardware cisco asr_9000v-v2 - No
Hardware cisco asr_9001 - No
Hardware cisco asr_9006 - No
Hardware cisco asr_9010 - No
Hardware cisco asr_9901 - No
Hardware cisco asr_9902 - No
Hardware cisco asr_9903 - No
Hardware cisco asr_9904 - No
Hardware cisco asr_9906 - No
Hardware cisco asr_9910 - No
Hardware cisco asr_9912 - No
Hardware cisco asr_9922 - No
Hardware cisco catalyst_3650 - No
Hardware cisco catalyst_3850 - No
Hardware cisco catalyst_8200 - No
Hardware cisco catalyst_8300 - No
Hardware cisco catalyst_8500 - No
Hardware cisco catalyst_8500l - No
Hardware cisco catalyst_9200 - No
Hardware cisco catalyst_9300 - No
Hardware cisco catalyst_9400 - No
Hardware cisco catalyst_9500 - No
Hardware cisco catalyst_9500h - No
Hardware cisco catalyst_9600 - No
Hardware cisco catalyst_9800 - No
Hardware cisco catalyst_9800-40 - No
Hardware cisco catalyst_9800-80 - No
Hardware cisco catalyst_9800-cl - No
Hardware cisco catalyst_9800-l - No
Hardware cisco catalyst_cg418-e - No
Hardware cisco catalyst_cg522-e - No
Hardware cisco catalyst_ess9300 - No
Hardware cisco catalyst_ie3200 - No
Hardware cisco catalyst_ie3300 - No
Hardware cisco catalyst_ie3400 - No
Hardware cisco catalyst_ie9300 - No
Hardware cisco cloud_services_router_1000v - No
Hardware cisco esr3300 - No
Hardware cisco esr6300 - No

References