PT-2022-5475 · Cisco · Cisco Secure Web Appliance+2
Published
2022-11-02
·
Updated
2024-01-25
·
CVE-2022-20868
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Email Security Appliance (affected versions not specified)
Cisco Secure Email and Web Manager (affected versions not specified)
Cisco Secure Web Appliance (affected versions not specified)
Description
The issue is related to the use of a hardcoded cryptographic key in the web-based management interface of the affected systems. This could allow an authenticated, remote attacker to elevate privileges on an affected system by sending a crafted HTTP request. The attacker needs valid credentials to exploit this vulnerability. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.
Recommendations
For Cisco Email Security Appliance, consider disabling the
jwt api impl function until a patch is available.
For Cisco Secure Email and Web Manager, restrict access to the web-based management interface to minimize the risk of exploitation.
For Cisco Secure Web Appliance, avoid using the hardcoded JWT secret in API calls until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Email Security Appliance
Cisco Secure Email/Web Manager
Cisco Secure Web Appliance