CVE-2022-20722: Cisco IOx Application Hosting Environment Vulnerabilities
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20722?
CVE-2022-20722 has been classified as a medium severity vulnerability.
How do I fix CVE-2022-20722?
To remediate CVE-2022-20722, upgrade to the latest version of Cisco IOS XE that addresses this vulnerability.
What types of systems are affected by CVE-2022-20722?
CVE-2022-20722 affects multiple versions of Cisco IOS XE on various Cisco platforms.
What are the potential impacts of CVE-2022-20722?
The impacts of CVE-2022-20722 include unauthorized command injection and arbitrary code execution on the host operating system.
Is there a workaround for CVE-2022-20722?
Currently, the recommended action for CVE-2022-20722 is to apply the security patches provided by Cisco.