PT-2022-1962 · Cisco · Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure

Andrew Kim

·

Published

2022-03-02

·

Updated

2023-07-24

·

CVE-2022-20762

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) (affected versions not specified)
Description The issue is related to insufficient access control in the Common Execution Environment (CEE) ConfD CLI, which could allow an authenticated, local attacker to escalate privileges on an affected device. An attacker could exploit this by authenticating as a CEE ConfD CLI user and executing a specific CLI command, potentially accessing privileged containers with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-01522
CVE-2022-20762

Affected Products

Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure