PT-2022-5688 · Cisco · Cisco Secure Firewalls 3100 Series+1

Published

2022-11-09

·

Updated

2024-01-25

·

CVE-2022-20826

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Secure Firewalls 3100 Series versions (affected versions not specified)
Description A vulnerability in the secure boot implementation could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This issue is due to a logic error in the boot process. An attacker could exploit this by injecting malicious code into a specific memory location during the boot process, potentially allowing the execution of persistent code at boot time and breaking the chain of trust.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2022-07083
CVE-2022-20826

Affected Products

Cisco Asa
Cisco Secure Firewalls 3100 Series