CVE-2022-20828 Details
Description
A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit this vulnerability, the attacker must have administrative access to the Cisco ASA. A user who has administrative access to a particular Cisco ASA is also expected to have administrative access to the ASA FirePOWER module that is hosted by that Cisco ASA.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 1, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-236 | Improper Handling of Undefined Parameters | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco asa firepower | < 6.2.3.19 >= 6.3.0, < 6.4.0.15 >= 6.5.0, < 6.6.7 >= 6.7.0, < 7.0.2.1 |
CPE
Remediation
| |
| cisco firepower 1010 | All versions |
CPE
Remediation
| |
| cisco firepower 1120 | All versions |
CPE
Remediation
| |
| cisco firepower 1140 | All versions |
CPE
Remediation
| |
| cisco firepower 1150 | All versions |
CPE
Remediation
| |
| cisco firepower 2110 | All versions |
CPE
Remediation
| |
| cisco firepower 2120 | All versions |
CPE
Remediation
| |
| cisco firepower 2130 | All versions |
CPE
Remediation
| |
| cisco firepower 2140 | All versions |
CPE
Remediation
| |
| cisco firepower 4110 | All versions |
CPE
Remediation
| |
| cisco firepower 4112 | All versions |
CPE
Remediation
| |
| cisco firepower 4115 | All versions |
CPE
Remediation
| |
| cisco firepower 4120 | All versions |
CPE
Remediation
| |
| cisco firepower 4125 | All versions |
CPE
Remediation
| |
| cisco firepower 4140 | All versions |
CPE
Remediation
| |
| cisco firepower 4145 | All versions |
CPE
Remediation
| |
| cisco firepower 4150 | All versions |
CPE
Remediation
| |
| cisco firepower 9300 | All versions |
CPE
Remediation
| |
| cisco firepower management center | All versions |
CPE
Remediation
| |
| cisco firepower management center virtual appliance | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 26, 2022 | Modified Analysis | [email protected] |
| Sep 5, 2022 | CVE Modified | [email protected] |
| Aug 16, 2022 | CVE Modified | [email protected] |
| Jul 6, 2022 | Initial Analysis | [email protected] |