CVE-2022-20918
CVSS V2 None
CVSS V3 High 7.5
Description
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated, remote attacker to perform an SNMP GET request using a default credential. This vulnerability is due to the presence of a default credential for SNMP version 1 (SNMPv1) and SNMP version 2 (SNMPv2). An attacker could exploit this vulnerability by sending an SNMPv1 or SNMPv2 GET request to an affected device. A successful exploit could allow the attacker to retrieve sensitive information from the device using the default credential. This attack will only be successful if SNMP is configured, and the attacker can only perform SNMP GET requests; write access using SNMP is not allowed.
Overview
- CVE ID
- CVE-2022-20918
- Assigner
- ykramarz@cisco.com
- Vulnerability Status
- Analyzed
- Published Version
- 2022-11-15T21:15:29
- Last Modified Date
- 2022-11-22T00:48:02
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:cisco:firepower_management_center:*:*:*:*:*:*:*:* | 1 | OR | 7.0.0 | 7.0.5 |
cpe:2.3:a:cisco:firepower_services_software_for_asa:-:*:*:*:*:*:*:* | 1 | OR |
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 7.5
- Base Severity
- HIGH
- Exploitability Score
- 3.9
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcsfr-snmp-access-6gqgtJ4S |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-20918 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20918 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-11-15 22:00:14 | Added to TrackCVE | |||
2022-12-07 17:47:38 | psirt@cisco.com | ykramarz@cisco.com | CVE Assigner | updated |
2022-12-07 17:47:38 | 2022-11-15T21:15Z | 2022-11-15T21:15:29 | CVE Published Date | updated |
2022-12-07 17:47:38 | 2022-11-22T00:48:02 | CVE Modified Date | updated | |
2022-12-07 17:47:38 | Analyzed | Vulnerability Status | updated | |
2022-12-07 17:47:39 | CPE Information | updated |