Rewterz
Rewterz Threat Alert – LokiBot Malware – Active IOCs
June 24, 2022
Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
June 24, 2022

Rewterz Threat Advisory – CVE-2022-20828 – Cisco FirePOWER Software for ASA FirePOWER Module Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-20828

Cisco FirePOWER Software for ASA FirePOWER Module could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by improper handling of undefined command parameters. By using a specially-crafted command on the CLI or by submitting a specially-crafted HTTPS request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.

Impact

  • Command Execution

Indicators Of Compromise

CVE

  • CVE-2022-20828

Affected Vendors

  • Cisco

Affected Products

  • Cisco FirePOWER Software for ASA FirePOWER Module Release 6.2.2
  • Cisco FirePOWER Software for ASA FirePOWER Module Release 6.2.3
  • Cisco FirePOWER Software for ASA FirePOWER Module Release 6.3.0
  • Cisco FirePOWER Software for ASA FirePOWER Module Release 6.4.0

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory