CVE-2022-20725

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Path Traversal
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
ciscoCNA
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
ciscocgr1000_compute_module
*
ciscoic3000_industrial_compute_gateway
*
ciscoir510_operating_system
*
ciscoios
15.2\(5\)e1
ciscoios
15.2\(5\)e2c
ciscoios
15.2\(6\)e0a
ciscoios
15.2\(6\)e1
ciscoios
15.2\(6\)e2a
ciscoios
15.2\(7\)e
ciscoios
15.2\(7\)e0b
ciscoios
15.2\(7\)e0s
ciscoios
15.6\(1\)t1
ciscoios
15.6\(1\)t2
ciscoios
15.6\(1\)t3
ciscoios
15.6\(2\)t
ciscoios
15.6\(2\)t0a
ciscoios
15.6\(2\)t1
ciscoios
15.6\(2\)t2
ciscoios
15.6\(2\)t3
ciscoios
15.6\(3\)m
ciscoios
15.6\(3\)m0a
ciscoios
15.6\(3\)m1
ciscoios
15.6\(3\)m1a
ciscoios
15.6\(3\)m1b
ciscoios
15.6\(3\)m2
ciscoios
15.6\(3\)m2a
ciscoios
15.6\(3\)m3
ciscoios
15.6\(3\)m3a
ciscoios
15.6\(3\)m4
ciscoios
15.6\(3\)m5
ciscoios
15.6\(3\)m6
ciscoios
15.6\(3\)m6a
ciscoios
15.6\(3\)m6b
ciscoios
15.6\(3\)m7
ciscoios
15.6\(3\)m8
ciscoios
15.6\(3\)m9
ciscoios
15.7\(3\)m
ciscoios
15.7\(3\)m0a
ciscoios
15.7\(3\)m1
ciscoios
15.7\(3\)m2
ciscoios
15.7\(3\)m3
ciscoios
15.7\(3\)m4
ciscoios
15.7\(3\)m4a
ciscoios
15.7\(3\)m4b
ciscoios
15.7\(3\)m5
ciscoios
15.7\(3\)m6
ciscoios
15.7\(3\)m7
ciscoios
15.7\(3\)m8
ciscoios
15.7\(3\)m9
ciscoios
15.8\(3\)m
ciscoios
15.8\(3\)m0a
ciscoios
15.8\(3\)m0b
ciscoios
15.8\(3\)m1
ciscoios
15.8\(3\)m1a
ciscoios
15.8\(3\)m2
ciscoios
15.8\(3\)m2a
ciscoios
15.8\(3\)m3
ciscoios
15.8\(3\)m3a
ciscoios
15.8\(3\)m3b
ciscoios
15.8\(3\)m4
ciscoios
15.8\(3\)m5
ciscoios
15.8\(3\)m6
ciscoios
15.8\(3\)m7
ciscoios
15.9\(3\)m
ciscoios
15.9\(3\)m0a
ciscoios
15.9\(3\)m1
ciscoios
15.9\(3\)m2
ciscoios
15.9\(3\)m2a
ciscoios
15.9\(3\)m3
ciscoios
15.9\(3\)m3a
ciscoios
15.9\(3\)m3b
ciscoios
15.9\(3\)m4
ciscoios
15.9\(3\)m4a
ciscoios_xe
16.3.1
ciscoios_xe
16.3.1a:a
ciscoios_xe
16.3.2
ciscoios_xe
16.3.3
ciscoios_xe
16.3.4
ciscoios_xe
16.3.5
ciscoios_xe
16.3.5b:b
ciscoios_xe
16.3.6
ciscoios_xe
16.3.7
ciscoios_xe
16.3.8
ciscoios_xe
16.3.9
ciscoios_xe
16.3.10
ciscoios_xe
16.3.11
ciscoios_xe
16.4.1
ciscoios_xe
16.4.2
ciscoios_xe
16.4.3
ciscoios_xe
16.5.1
ciscoios_xe
16.5.1a:a
ciscoios_xe
16.5.1b:b
ciscoios_xe
16.5.2
ciscoios_xe
16.5.3
ciscoios_xe
16.6.1
ciscoios_xe
16.6.2
ciscoios_xe
16.6.3
ciscoios_xe
16.6.4
ciscoios_xe
16.6.4a:a
ciscoios_xe
16.6.4s:s
ciscoios_xe
16.6.5
ciscoios_xe
16.6.5a:a
ciscoios_xe
16.6.5b:b
ciscoios_xe
16.6.6
ciscoios_xe
16.6.7
ciscoios_xe
16.6.7a:a
ciscoios_xe
16.6.8
ciscoios_xe
16.6.9
ciscoios_xe
16.6.10
ciscoios_xe
16.7.1
ciscoios_xe
16.7.1a:a
ciscoios_xe
16.7.1b:b
ciscoios_xe
16.7.2
ciscoios_xe
16.7.3
ciscoios_xe
16.7.4
ciscoios_xe
16.8.1
ciscoios_xe
16.8.1a:a
ciscoios_xe
16.8.1b:b
ciscoios_xe
16.8.1c:c
ciscoios_xe
16.8.1d:d
ciscoios_xe
16.8.1e:e
ciscoios_xe
16.8.1s:s
ciscoios_xe
16.8.2
ciscoios_xe
16.8.3
ciscoios_xe
16.9.1
ciscoios_xe
16.9.1a:a
ciscoios_xe
16.9.1b:b
ciscoios_xe
16.9.1c:c
ciscoios_xe
16.9.1d:d
ciscoios_xe
16.9.1s:s
ciscoios_xe
16.9.2
ciscoios_xe
16.9.2a:a
ciscoios_xe
16.9.2s:s
ciscoios_xe
16.9.3
ciscoios_xe
16.9.3a:a
ciscoios_xe
16.9.3h:h
ciscoios_xe
16.9.3s:s
ciscoios_xe
16.9.4
ciscoios_xe
16.9.4c:c
ciscoios_xe
16.9.5
ciscoios_xe
16.9.5f:f
ciscoios_xe
16.9.6
ciscoios_xe
16.9.7
ciscoios_xe
16.9.8
ciscoios_xe
16.10.1
ciscoios_xe
16.10.1a:a
ciscoios_xe
16.10.1b:b
ciscoios_xe
16.10.1c:c
ciscoios_xe
16.10.1d:d
ciscoios_xe
16.10.1e:e
ciscoios_xe
16.10.1f:f
ciscoios_xe
16.10.1g:g
ciscoios_xe
16.10.1s:s
ciscoios_xe
16.10.2
ciscoios_xe
16.10.3
ciscoios_xe
16.11.1
ciscoios_xe
16.11.1a:a
ciscoios_xe
16.11.1b:b
ciscoios_xe
16.11.1c:c
ciscoios_xe
16.11.1s:s
ciscoios_xe
16.11.2
ciscoios_xe
16.12.1
ciscoios_xe
16.12.1a:a
ciscoios_xe
16.12.1c:c
ciscoios_xe
16.12.1s:s
ciscoios_xe
16.12.1t:t
ciscoios_xe
16.12.1w:w
ciscoios_xe
16.12.1x:x
ciscoios_xe
16.12.1y:y
ciscoios_xe
16.12.2
ciscoios_xe
16.12.2a:a
ciscoios_xe
16.12.2s:s
ciscoios_xe
16.12.2t:t
ciscoios_xe
16.12.3
ciscoios_xe
16.12.3a:a
ciscoios_xe
16.12.3s:s
ciscoios_xe
16.12.4
ciscoios_xe
16.12.4a:a
ciscoios_xe
16.12.5
ciscoios_xe
16.12.5a:a
ciscoios_xe
17.1.1
ciscoios_xe
17.1.1a:a
ciscoios_xe
17.1.1s:s
ciscoios_xe
17.1.1t:t
ciscoios_xe
17.1.2
ciscoios_xe
17.1.3
ciscoios_xe
17.2.1
ciscoios_xe
17.2.1a:a
ciscoios_xe
17.2.1r:r
ciscoios_xe
17.2.1v:v
ciscoios_xe
17.2.2
ciscoios_xe
17.2.3
ciscoios_xe
17.3.1
ciscoios_xe
17.3.1a:a
ciscoios_xe
17.3.1w:w
ciscoios_xe
17.3.1x:x
ciscoios_xe
17.3.1z:z
ciscoios_xe
17.3.2
ciscoios_xe
17.3.2a:a
ciscoios_xe
17.3.3
ciscoios_xe
17.3.3a:a
ciscoios_xe
17.3.4
ciscoios_xe
17.3.4a:a
ciscoios_xe
17.3.4b:b
ciscoios_xe
17.3.4c:c
ciscoios_xe
17.4.1
ciscoios_xe
17.4.1a:a
ciscoios_xe
17.4.1b:b
ciscoios_xe
17.4.1c:c
ciscoios_xe
17.4.2
ciscoios_xe
17.4.2a:a
ciscoios_xe
17.5.1
ciscoios_xe
17.5.1a:a
ciscoios_xe
17.6.1
ciscoios_xe
17.6.1a:a
𝑥
= Vulnerable software versions