CVE-2022-20942: Medium severity cisco asyncos software vulnerability
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain confidential data that is stored on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20942?
CVE-2022-20942 is a vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance.
How can an attacker exploit CVE-2022-20942?
An authenticated, remote attacker can exploit CVE-2022-20942 to retrieve sensitive information.
What is the severity of CVE-2022-20942?
CVE-2022-20942 has a severity rating of 6.5 (Medium).
Which software versions are affected by CVE-2022-20942?
CVE-2022-20942 affects Cisco AsyncOS versions up to and excluding 14.2.1-015 and versions up to and excluding 14.3.0-023.
How can I fix CVE-2022-20942?
To fix CVE-2022-20942, update to a version of Cisco AsyncOS that is not affected by the vulnerability.