Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-20759 Details

Description

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device. This includes privilege level 15 access to the device using management tools like the Cisco Adaptive Security Device Manager (ASDM) or the Cisco Security Manager (CSM). Note: With Cisco FTD Software, the impact is lower than the CVSS score suggests because the affected web management interface allows for read access only.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege Management[email protected]
CWE-266Incorrect Privilege Assignment[email protected]

Affected Products

ProductVersions
cisco secure firewall threat defense
< 6.4.0.15
>= 6.5.0, < 6.6.5.2
>= 6.7.0, < 7.0.2
7.1.0

CPE

  • cpe:2.3:a:cisco:secure_firewall_threat_defense:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco adaptive security appliance software
< 9.12.4.38
>= 9.13.0, < 9.14.4
>= 9.15.0, < 9.15.1.21
>= 9.16.0, < 9.16.2.14
>= 9.17.0, < 9.17.1.7

CPE

  • cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-20759
NVD Published Date:
May 3, 2022
NVD Last Modified:
Aug 11, 2026
Source:
[email protected]
CVE-2022-20759 Details - Not Deferred