PT-2022-2321 · Cisco · Cisco Umbrella Virtual Appliance

Fraser Hess

·

Published

2022-04-20

·

Updated

2022-05-04

·

CVE-2022-20773

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Umbrella Virtual Appliance (VA) (affected versions not specified)
Description The issue is related to the key-based SSH authentication mechanism, which uses a static SSH host key, allowing a remote attacker to perform a man-in-the-middle attack on an SSH connection. This could enable the attacker to impersonate the VA, learn administrator credentials, change configurations, or reload the VA. It is noted that SSH is not enabled by default on the Umbrella VA.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02511
CVE-2022-20773

Affected Products

Cisco Umbrella Virtual Appliance