CVE-2022-20759
Cisco Cisco Adaptive Security Appliance (ASA) Software, secure firewall threat defense, adaptive security appliance software
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web man...
- CVSS
- 8.8
- EPSS
- 29.2% 98.0% percentile
- CISA KEV
- Not listed
- Published
- 2022.05.03