Vulnerability Change Records for CVE-2022-20655
Change History
New CVE Received from Cisco Systems, Inc. 11/15/2024 11:15:20 AM
| Action |
Type |
Old Value |
New Value |
| Added |
Description |
|
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack.
The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.
|
| Added |
CVSS V3.1 |
|
Cisco Systems, Inc. AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| Added |
CWE |
|
Cisco Systems, Inc. CWE-78
|
| Added |
Reference |
|
Cisco Systems, Inc. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cli-cmdinj-4MttWZPB [No types assigned]
|
| Added |
Reference |
|
Cisco Systems, Inc. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-confdcli-cmdinj-wybQDSSh [No types assigned]
|
|