CVE-2022-20866
Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance software, secure firewall threat defense
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following con...
- CVSS
- 7.5
- EPSS
- 17.2% 96.8% percentile
- CISA KEV
- Not listed
- Published
- 2022.08.11