PT-2022-5475 · Cisco · Cisco Secure Web Appliance+2

Published

2022-11-02

·

Updated

2024-01-25

·

CVE-2022-20868

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Email Security Appliance (affected versions not specified) Cisco Secure Email and Web Manager (affected versions not specified) Cisco Secure Web Appliance (affected versions not specified)
Description The issue is related to the use of a hardcoded cryptographic key in the web-based management interface of the affected systems. This could allow an authenticated, remote attacker to elevate privileges on an affected system by sending a crafted HTTP request. The attacker needs valid credentials to exploit this vulnerability. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.
Recommendations For Cisco Email Security Appliance, consider disabling the jwt api impl function until a patch is available. For Cisco Secure Email and Web Manager, restrict access to the web-based management interface to minimize the risk of exploitation. For Cisco Secure Web Appliance, avoid using the hardcoded JWT secret in API calls until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-06804
CVE-2022-20868

Affected Products

Cisco Email Security Appliance
Cisco Secure Email/Web Manager
Cisco Secure Web Appliance