Rewterz

Rewterz Threat Alert – DoNot APT Team Added New Tricks And Techniques To Its Kit – Active IOCs

August 19, 2022
Rewterz

Rewterz Threat Alert – LockBit Ransomware Claimed Attack on Security Giant Entrust

August 19, 2022

Rewterz Threat Advisory – CVE-2022-20871 – Cisco Secure Web Appliance Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-20871

Cisco Secure Web Appliance could allow a remote authenticated attacker to gain elevated privileges on the system, caused by insufficient validation of user-supplied input for the web interface. By authenticating to the system and sending a crafted HTTP packet to the affected device, an attacker could exploit this vulnerability to execute arbitrary commands on the underlying operating system and elevate privileges to root.

Impact

  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2022-20871

Affected Vendors

Cisco

Affected Products

Cisco AsyncOS for Secure Web Appliance

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.