CVE-2022-20726: Cisco IOx Application Hosting Environment Vulnerabilities
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20726?
CVE-2022-20726 is rated as critical due to its potential to allow remote code execution on affected Cisco devices.
How do I fix CVE-2022-20726?
To fix CVE-2022-20726, users should update affected devices to the latest Cisco IOS version that addresses this vulnerability.
What platforms are affected by CVE-2022-20726?
CVE-2022-20726 affects multiple Cisco platforms, including the CGR 1000 Compute Module and various versions of Cisco IOS.
How can CVE-2022-20726 be exploited?
Attackers can exploit CVE-2022-20726 by injecting malicious commands into the underlying host operating system of affected devices.
What are the potential impacts of CVE-2022-20726?
The potential impacts of CVE-2022-20726 include unauthorized access, data loss, system compromise, and the ability to execute arbitrary code.