CVE-2022-20719: Cisco IOx Application Hosting Environment Vulnerabilities
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20719?
CVE-2022-20719 is rated as high severity due to its potential to allow arbitrary command injection and code execution on the underlying host operating system.
How do I fix CVE-2022-20719?
To fix CVE-2022-20719, you should update the affected Cisco IOS XE or IR510 Operating Systems to the latest versions recommended by Cisco.
What platforms are affected by CVE-2022-20719?
CVE-2022-20719 affects multiple Cisco platforms running the Cisco IOx application hosting environment.
What types of attacks can be executed through CVE-2022-20719?
Exploitation of CVE-2022-20719 can allow attackers to inject arbitrary commands and execute malicious code on the underlying host operating system.
Is CVE-2022-20719 actively being exploited?
As of now, there is no public indication that CVE-2022-20719 is actively being exploited in the wild, but organizations should still apply mitigations promptly.