Vulnslist

find the latest Cisco vulnerabilities

CVE-2022-20928

A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the authorization verifications during the VPN authentication flow. An attacker could exploit this vulnerability by sending a crafted packet during a VPN authentication. The attacker must have valid credentials to establish a VPN connection. A successful exploit could allow the attacker to establish a VPN connection with access privileges from a different user.

SeverityMEDIUM
CVSS5.8
CWECWE-863
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Secure Firewall Threat Defense Virtual cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Secure Firewall Threat Defense (FTD) Software cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Secure Firewall 3100 Series cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Firepower Threat Defense Software cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Firepower 9000 Series cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Firepower 4100 Series cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Firepower 2100 Series cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Firepower 1000 Series cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco FirePOWER Services Software for ASA cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Adaptive Security Virtual Appliance (ASAv) cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco ASA 5500-X Series Firewalls cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln
Cisco 3000 Series Industrial Security Appliances (ISA) cisco-sa-asa-ftd-vp-authz-N2GckjN6 Cisco OpenVuln