CWE
79 22
Advisory Published
Updated

CVE-2022-20725: XSS

First published: Fri Apr 15 2022(Updated: )

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.

Credit: ykramarz@cisco.com ykramarz@cisco.com

Affected SoftwareAffected VersionHow to fix
Cisco Cgr1000 Compute Module
Cisco IC3000 Industrial Compute Gateway
Cisco Ir510 Operating System
Cisco IOS=15.2\(5\)e1
Cisco IOS=15.2\(5\)e2c
Cisco IOS=15.2\(6\)e0a
Cisco IOS=15.2\(6\)e1
Cisco IOS=15.2\(6\)e2a
Cisco IOS=15.2\(7\)e
Cisco IOS=15.2\(7\)e0b
Cisco IOS=15.2\(7\)e0s
Cisco IOS=15.6\(1\)t1
Cisco IOS=15.6\(1\)t2
Cisco IOS=15.6\(1\)t3
Cisco IOS=15.6\(2\)t
Cisco IOS=15.6\(2\)t0a
Cisco IOS=15.6\(2\)t1
Cisco IOS=15.6\(2\)t2
Cisco IOS=15.6\(2\)t3
Cisco IOS=15.6\(3\)m
Cisco IOS=15.6\(3\)m0a
Cisco IOS=15.6\(3\)m1
Cisco IOS=15.6\(3\)m1a
Cisco IOS=15.6\(3\)m1b
Cisco IOS=15.6\(3\)m2
Cisco IOS=15.6\(3\)m2a
Cisco IOS=15.6\(3\)m3
Cisco IOS=15.6\(3\)m3a
Cisco IOS=15.6\(3\)m4
Cisco IOS=15.6\(3\)m5
Cisco IOS=15.6\(3\)m6
Cisco IOS=15.6\(3\)m6a
Cisco IOS=15.6\(3\)m6b
Cisco IOS=15.6\(3\)m7
Cisco IOS=15.6\(3\)m8
Cisco IOS=15.6\(3\)m9
Cisco IOS=15.7\(3\)m
Cisco IOS=15.7\(3\)m0a
Cisco IOS=15.7\(3\)m1
Cisco IOS=15.7\(3\)m2
Cisco IOS=15.7\(3\)m3
Cisco IOS=15.7\(3\)m4
Cisco IOS=15.7\(3\)m4a
Cisco IOS=15.7\(3\)m4b
Cisco IOS=15.7\(3\)m5
Cisco IOS=15.7\(3\)m6
Cisco IOS=15.7\(3\)m7
Cisco IOS=15.7\(3\)m8
Cisco IOS=15.7\(3\)m9
Cisco IOS=15.8\(3\)m
Cisco IOS=15.8\(3\)m0a
Cisco IOS=15.8\(3\)m0b
Cisco IOS=15.8\(3\)m1
Cisco IOS=15.8\(3\)m1a
Cisco IOS=15.8\(3\)m2
Cisco IOS=15.8\(3\)m2a
Cisco IOS=15.8\(3\)m3
Cisco IOS=15.8\(3\)m3a
Cisco IOS=15.8\(3\)m3b
Cisco IOS=15.8\(3\)m4
Cisco IOS=15.8\(3\)m5
Cisco IOS=15.8\(3\)m6
Cisco IOS=15.8\(3\)m7
Cisco IOS=15.9\(3\)m
Cisco IOS=15.9\(3\)m0a
Cisco IOS=15.9\(3\)m1
Cisco IOS=15.9\(3\)m2
Cisco IOS=15.9\(3\)m2a
Cisco IOS=15.9\(3\)m3
Cisco IOS=15.9\(3\)m3a
Cisco IOS=15.9\(3\)m3b
Cisco IOS=15.9\(3\)m4
Cisco IOS=15.9\(3\)m4a
Cisco IOS XE=16.3.1
Cisco IOS XE=16.3.1a
Cisco IOS XE=16.3.2
Cisco IOS XE=16.3.3
Cisco IOS XE=16.3.4
Cisco IOS XE=16.3.5
Cisco IOS XE=16.3.5b
Cisco IOS XE=16.3.6
Cisco IOS XE=16.3.7
Cisco IOS XE=16.3.8
Cisco IOS XE=16.3.9
Cisco IOS XE=16.3.10
Cisco IOS XE=16.3.11
Cisco IOS XE=16.4.1
Cisco IOS XE=16.4.2
Cisco IOS XE=16.4.3
Cisco IOS XE=16.5.1
Cisco IOS XE=16.5.1a
Cisco IOS XE=16.5.1b
Cisco IOS XE=16.5.2
Cisco IOS XE=16.5.3
Cisco IOS XE=16.6.1
Cisco IOS XE=16.6.2
Cisco IOS XE=16.6.3
Cisco IOS XE=16.6.4
Cisco IOS XE=16.6.4a
Cisco IOS XE=16.6.4s
Cisco IOS XE=16.6.5
Cisco IOS XE=16.6.5a
Cisco IOS XE=16.6.5b
Cisco IOS XE=16.6.6
Cisco IOS XE=16.6.7
Cisco IOS XE=16.6.7a
Cisco IOS XE=16.6.8
Cisco IOS XE=16.6.9
Cisco IOS XE=16.6.10
Cisco IOS XE=16.7.1
Cisco IOS XE=16.7.1a
Cisco IOS XE=16.7.1b
Cisco IOS XE=16.7.2
Cisco IOS XE=16.7.3
Cisco IOS XE=16.7.4
Cisco IOS XE=16.8.1
Cisco IOS XE=16.8.1a
Cisco IOS XE=16.8.1b
Cisco IOS XE=16.8.1c
Cisco IOS XE=16.8.1d
Cisco IOS XE=16.8.1e
Cisco IOS XE=16.8.1s
Cisco IOS XE=16.8.2
Cisco IOS XE=16.8.3
Cisco IOS XE=16.9.1
Cisco IOS XE=16.9.1a
Cisco IOS XE=16.9.1b
Cisco IOS XE=16.9.1c
Cisco IOS XE=16.9.1d
Cisco IOS XE=16.9.1s
Cisco IOS XE=16.9.2
Cisco IOS XE=16.9.2a
Cisco IOS XE=16.9.2s
Cisco IOS XE=16.9.3
Cisco IOS XE=16.9.3a
Cisco IOS XE=16.9.3h
Cisco IOS XE=16.9.3s
Cisco IOS XE=16.9.4
Cisco IOS XE=16.9.4c
Cisco IOS XE=16.9.5
Cisco IOS XE=16.9.5f
Cisco IOS XE=16.9.6
Cisco IOS XE=16.9.7
Cisco IOS XE=16.9.8
Cisco IOS XE=16.10.1
Cisco IOS XE=16.10.1a
Cisco IOS XE=16.10.1b
Cisco IOS XE=16.10.1c
Cisco IOS XE=16.10.1d
Cisco IOS XE=16.10.1e
Cisco IOS XE=16.10.1f
Cisco IOS XE=16.10.1g
Cisco IOS XE=16.10.1s
Cisco IOS XE=16.10.2
Cisco IOS XE=16.10.3
Cisco IOS XE=16.11.1
Cisco IOS XE=16.11.1a
Cisco IOS XE=16.11.1b
Cisco IOS XE=16.11.1c
Cisco IOS XE=16.11.1s
Cisco IOS XE=16.11.2
Cisco IOS XE=16.12.1
Cisco IOS XE=16.12.1a
Cisco IOS XE=16.12.1c
Cisco IOS XE=16.12.1s
Cisco IOS XE=16.12.1t
Cisco IOS XE=16.12.1w
Cisco IOS XE=16.12.1x
Cisco IOS XE=16.12.1y
Cisco IOS XE=16.12.2
Cisco IOS XE=16.12.2a
Cisco IOS XE=16.12.2s
Cisco IOS XE=16.12.2t
Cisco IOS XE=16.12.3
Cisco IOS XE=16.12.3a
Cisco IOS XE=16.12.3s
Cisco IOS XE=16.12.4
Cisco IOS XE=16.12.4a
Cisco IOS XE=16.12.5
Cisco IOS XE=16.12.5a
Cisco IOS XE=17.1.1
Cisco IOS XE=17.1.1a
Cisco IOS XE=17.1.1s
Cisco IOS XE=17.1.1t
Cisco IOS XE=17.1.2
Cisco IOS XE=17.1.3
Cisco IOS XE=17.2.1
Cisco IOS XE=17.2.1a
Cisco IOS XE=17.2.1r
Cisco IOS XE=17.2.1v
Cisco IOS XE=17.2.2
Cisco IOS XE=17.2.3
Cisco IOS XE=17.3.1
Cisco IOS XE=17.3.1a
Cisco IOS XE=17.3.1w
Cisco IOS XE=17.3.1x
Cisco IOS XE=17.3.1z
Cisco IOS XE=17.3.2
Cisco IOS XE=17.3.2a
Cisco IOS XE=17.3.3
Cisco IOS XE=17.3.3a
Cisco IOS XE=17.3.4
Cisco IOS XE=17.3.4a
Cisco IOS XE=17.3.4b
Cisco IOS XE=17.3.4c
Cisco IOS XE=17.4.1
Cisco IOS XE=17.4.1a
Cisco IOS XE=17.4.1b
Cisco IOS XE=17.4.1c
Cisco IOS XE=17.4.2
Cisco IOS XE=17.4.2a
Cisco IOS XE=17.5.1
Cisco IOS XE=17.5.1a
Cisco IOS XE=17.6.1
Cisco IOS XE=17.6.1a
Cisco 800m Integrated Services Router
Cisco 807 Industrial Integrated Services Router
Cisco 812 3g Integrated Services Router
Cisco 812 Cifi Integrated Services Router
Cisco 819 Hardened Dual Radio 802.11n Wifi Integrated Services Router
Cisco 819 Hardened Integrated Services Router
Cisco 829 Industrial Integrated Services Router
Cisco 860vae-w Integrated Services Router
Cisco 861 Integrated Services Router
Cisco 861w Integrated Services Router
Cisco 866vae Integrated Services Router
Cisco 867 Integrated Services Router
Cisco 867vae Integrated Services Router
Cisco 880-voice Integrated Services Router
Cisco 880 3g Integrated Services Router
Cisco 881-cube Integrated Services Router
Cisco 881 3g Integrated Services Router
Cisco 881 Integrated Services Router
Cisco 881w Integrated Services Router
Cisco 886 Integrated Services Router
Cisco 886va-cube Integrated Services Router
Cisco 886va-w Integrated Services Router
Cisco 886va Integrated Services Router
Cisco 886vag 3g Integrated Services Router
Cisco 887 Integrated Services Router
Cisco 887v Integrated Services Router
Cisco 887va-cube Integrated Services Router
Cisco 887va-w Integrated Services Router
Cisco 887va Integrated Services Router
Cisco 887vag 3g Integrated Services Router
Cisco 887vam-w Integrated Services Router
Cisco 887vamg 3g Integrated Services Router
Cisco 888-cube Integrated Services Router
Cisco 888 Integrated Services Router
Cisco 888e-cube Integrated Services Router
Cisco 888e Integrated Services Router
Cisco 888eg 3g Integrated Services Router
Cisco 888w Integrated Services Router
Cisco 891-24x Integrated Services Router
Cisco 891 Integrated Services Router
Cisco 891w Integrated Services Router
Cisco 892 Integrated Services Router
Cisco 892f-cube Integrated Services Router
Cisco 892w Integrated Services Router
Cisco Cgr 1000
Cisco Cgr 1120
Cisco Cgr 1240
Cisco IC3000 Industrial Compute Gateway
Cisco Ie-4000-16gt4g-e Industrial Ethernet Switch
Cisco Ie-4000-16t4g-e Industrial Ethernet Switch
Cisco Ie-4000-4gc4gp4g-e Industrial Ethernet Switch
Cisco Ie-4000-4gs8gp4g-e Industrial Ethernet Switch
Cisco Ie-4000-4s8p4g-e Industrial Ethernet Switch
Cisco Ie-4000-4t4p4g-e Industrial Ethernet Switch
Cisco Ie-4000-4tc4g-e Industrial Ethernet Switch
Cisco Ie-4000-8gs4g-e Industrial Ethernet Switch
Cisco Ie-4000-8gt4g-e Industrial Ethernet Switch
Cisco Ie-4000-8gt8gp4g-e Industrial Ethernet Switch
Cisco Ie-4000-8s4g-e Industrial Ethernet Switch
Cisco Ie-4000-8t4g-e Industrial Ethernet Switch
Cisco Ie-4010-16s12p Industrial Ethernet Switch
Cisco Ie-4010-4s24p Industrial Ethernet Switch
Cisco Ir510 Wpan

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203