{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T22:37:46.598","vulnerabilities":[{"cve":{"id":"CVE-2022-20871","sourceIdentifier":"psirt@cisco.com","published":"2024-11-15T16:15:23.757","lastModified":"2025-08-11T17:44:07.837","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the web management interface of Cisco&nbsp;AsyncOS for Cisco&nbsp;Secure Web Appliance, formerly Cisco&nbsp;Web Security Appliance (WSA),&nbsp;could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.\r\nThis vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by authenticating to the system and sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least read-only credentials.Cisco&nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.Attention: Simplifying the Cisco&nbsp;portfolio includes the renaming of security products under one brand: Cisco&nbsp;Secure. For more information, see ."},{"lang":"es","value":"Una vulnerabilidad en la interfaz de administración web de Cisco&#xa0;AsyncOS para Cisco&#xa0;Secure Web Appliance, anteriormente Cisco&#xa0;Web Security Appliance (WSA),&#xa0;podría permitir que un atacante remoto autenticado realice una inyección de comandos y eleve los privilegios a superusuario. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario para la interfaz web. Un atacante podría explotar esta vulnerabilidad autenticándose en el sistema y enviando un paquete HTTP diseñado al dispositivo afectado. Una explotación exitosa podría permitir al atacante ejecutar comandos arbitrarios en el sistema operativo subyacente y elevar los privilegios a superusuario. Para explotar con éxito esta vulnerabilidad, un atacante necesitaría al menos credenciales de solo lectura. Cisco&#xa0;ha publicado actualizaciones de software que solucionan esta vulnerabilidad. No existen workarounds que solucionen esta vulnerabilidad. Atención: la simplificación de la cartera de Cisco incluye el cambio de nombre de los productos de seguridad bajo una sola marca: Cisco&#xa0;Secure. Para obtener más información, consulte."}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.1-011:*:*:*:*:*:*:*","matchCriteriaId":"A2D22A3C-16D5-4F61-AB44-111F4A4D9F5C"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.2-007:*:*:*:*:*:*:*","matchCriteriaId":"8C79D794-0BA9-4A55-B843-FBF9B7374095"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.2-011:*:*:*:*:*:*:*","matchCriteriaId":"2536DCE8-4F1D-4056-A021-409B54C86ED9"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.3-002:*:*:*:*:*:*:*","matchCriteriaId":"2D75C030-216E-4019-ABA5-6DB662C6755C"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.4-005:*:*:*:*:*:*:*","matchCriteriaId":"BBE6E431-7859-4E92-88C5-C85DADC8A5D7"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:12.5.4-011:*:*:*:*:*:*:*","matchCriteriaId":"2FC0B862-5248-42D1-BB20-F957DD98A585"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:14.0.2-012:*:*:*:*:*:*:*","matchCriteriaId":"50BAC418-1CA1-4DB7-8B54-E4754A35F6E8"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:14.1.0-032:*:*:*:*:*:*:*","matchCriteriaId":"A1C5EDF4-868A-43B9-B5BA-0F62984F7BE5"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:14.1.0-041:*:*:*:*:*:*:*","matchCriteriaId":"45B7B8BB-91DA-490B-BA54-27AD44F862A4"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:14.1.0-047:*:*:*:*:*:*:*","matchCriteriaId":"16B7F282-1F20-4C84-A13E-C671BAE3F8D0"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:asyncos:14.5.0-498:*:*:*:*:*:*:*","matchCriteriaId":"60A56580-C34C-4E5D-B053-9D02F8DD9681"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:cisco:secure_web_appliance_virtual_s1000v:-:*:*:*:*:*:*:*","matchCriteriaId":"09BCBB0F-88F1-4469-A7D4-DA8BCAF5470A"},{"vulnerable":false,"criteria":"cpe:2.3:a:cisco:secure_web_appliance_virtual_s100v:-:*:*:*:*:*:*:*","matchCriteriaId":"2F88A369-E3A2-431A-AB71-CCD4F15E68EB"},{"vulnerable":false,"criteria":"cpe:2.3:a:cisco:secure_web_appliance_virtual_s300v:-:*:*:*:*:*:*:*","matchCriteriaId":"FE8ED2A4-8E08-420D-B377-6D1F5AF675DC"},{"vulnerable":false,"criteria":"cpe:2.3:a:cisco:secure_web_appliance_virtual_s600v:-:*:*:*:*:*:*:*","matchCriteriaId":"780EA177-5623-4AFF-9316-D557BE2BD47D"},{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:secure_web_appliance_s196:-:*:*:*:*:*:*:*","matchCriteriaId":"FE1F2FAF-C64B-4AEB-8DE4-329C61B8D17F"},{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:secure_web_appliance_s396:-:*:*:*:*:*:*:*","matchCriteriaId":"B5596058-16DB-46C0-82AC-D9BFC13F4126"},{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:secure_web_appliance_s696:-:*:*:*:*:*:*:*","matchCriteriaId":"62BEA59D-2AF1-4BDF-ACB3-450BED2E5AAB"}]}]}],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU","source":"psirt@cisco.com","tags":["Not Applicable"]},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dv","source":"psirt@cisco.com","tags":["Not Applicable"]},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}