CVE-2022-20723: Cisco IOx Application Hosting Environment Vulnerabilities
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20723?
CVE-2022-20723 has been rated as high severity, indicating a significant risk for affected systems.
How do I fix CVE-2022-20723?
To mitigate CVE-2022-20723, update your Cisco IOx application hosting environment to the latest versions provided in the security advisory.
Which versions of Cisco IOS XE are affected by CVE-2022-20723?
CVE-2022-20723 impacts multiple versions of Cisco IOS XE, specifically versions from 16.3.1 to 17.6.1.
What are the potential impacts of CVE-2022-20723?
Exploitation of CVE-2022-20723 could allow an attacker to execute arbitrary code on the host operating system.
Is there a patch available for CVE-2022-20723?
Yes, Cisco has released patches to address CVE-2022-20723, which can be obtained through their security update page.