CVE-2022-20928

A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user.

 This vulnerability is due to a flaw in the authorization verifications during the VPN authentication flow. An attacker could exploit this vulnerability by sending a crafted packet during a VPN authentication. The attacker must have valid credentials to establish a VPN connection. A successful exploit could allow the attacker to establish a VPN connection with access privileges from a different user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
ciscoCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
ciscoadaptive_security_appliance_software
9.6.1
ciscoadaptive_security_appliance_software
9.6.1.3
ciscoadaptive_security_appliance_software
9.6.1.5
ciscoadaptive_security_appliance_software
9.6.1.10
ciscoadaptive_security_appliance_software
9.6.2
ciscoadaptive_security_appliance_software
9.6.2.1
ciscoadaptive_security_appliance_software
9.6.2.2
ciscoadaptive_security_appliance_software
9.6.2.3
ciscoadaptive_security_appliance_software
9.6.2.7
ciscoadaptive_security_appliance_software
9.6.2.11
ciscoadaptive_security_appliance_software
9.6.2.13
ciscoadaptive_security_appliance_software
9.6.2.22
ciscoadaptive_security_appliance_software
9.6.2.23
ciscoadaptive_security_appliance_software
9.6.3
ciscoadaptive_security_appliance_software
9.6.3.1
ciscoadaptive_security_appliance_software
9.6.3.3
ciscoadaptive_security_appliance_software
9.6.3.8
ciscoadaptive_security_appliance_software
9.6.3.9
ciscoadaptive_security_appliance_software
9.6.3.11
ciscoadaptive_security_appliance_software
9.6.3.12
ciscoadaptive_security_appliance_software
9.6.3.14
ciscoadaptive_security_appliance_software
9.6.3.17
ciscoadaptive_security_appliance_software
9.6.3.20
ciscoadaptive_security_appliance_software
9.6.4
ciscoadaptive_security_appliance_software
9.6.4.3
ciscoadaptive_security_appliance_software
9.6.4.5
ciscoadaptive_security_appliance_software
9.6.4.6
ciscoadaptive_security_appliance_software
9.6.4.8
ciscoadaptive_security_appliance_software
9.6.4.10
ciscoadaptive_security_appliance_software
9.6.4.12
ciscoadaptive_security_appliance_software
9.6.4.14
ciscoadaptive_security_appliance_software
9.6.4.17
ciscoadaptive_security_appliance_software
9.6.4.18
ciscoadaptive_security_appliance_software
9.6.4.20
ciscoadaptive_security_appliance_software
9.6.4.22
ciscoadaptive_security_appliance_software
9.6.4.23
ciscoadaptive_security_appliance_software
9.6.4.24
ciscoadaptive_security_appliance_software
9.6.4.25
ciscoadaptive_security_appliance_software
9.6.4.29
ciscoadaptive_security_appliance_software
9.6.4.30
ciscoadaptive_security_appliance_software
9.6.4.34
ciscoadaptive_security_appliance_software
9.6.4.36
ciscoadaptive_security_appliance_software
9.6.4.40
ciscoadaptive_security_appliance_software
9.6.4.41
ciscoadaptive_security_appliance_software
9.6.4.42
ciscoadaptive_security_appliance_software
9.6.4.45
ciscoadaptive_security_appliance_software
9.7.1
ciscoadaptive_security_appliance_software
9.7.1.2
ciscoadaptive_security_appliance_software
9.7.1.4
ciscoadaptive_security_appliance_software
9.7.1.8
ciscoadaptive_security_appliance_software
9.7.1.15
ciscoadaptive_security_appliance_software
9.7.1.16
ciscoadaptive_security_appliance_software
9.7.1.21
ciscoadaptive_security_appliance_software
9.7.1.24
ciscoadaptive_security_appliance_software
9.8.1
ciscoadaptive_security_appliance_software
9.8.1.5
ciscoadaptive_security_appliance_software
9.8.1.7
ciscoadaptive_security_appliance_software
9.8.2
ciscoadaptive_security_appliance_software
9.8.2.8
ciscoadaptive_security_appliance_software
9.8.2.14
ciscoadaptive_security_appliance_software
9.8.2.15
ciscoadaptive_security_appliance_software
9.8.2.17
ciscoadaptive_security_appliance_software
9.8.2.20
ciscoadaptive_security_appliance_software
9.8.2.24
ciscoadaptive_security_appliance_software
9.8.2.26
ciscoadaptive_security_appliance_software
9.8.2.28
ciscoadaptive_security_appliance_software
9.8.2.33
ciscoadaptive_security_appliance_software
9.8.2.35
ciscoadaptive_security_appliance_software
9.8.2.38
ciscoadaptive_security_appliance_software
9.8.3
ciscoadaptive_security_appliance_software
9.8.3.8
ciscoadaptive_security_appliance_software
9.8.3.11
ciscoadaptive_security_appliance_software
9.8.3.14
ciscoadaptive_security_appliance_software
9.8.3.16
ciscoadaptive_security_appliance_software
9.8.3.18
ciscoadaptive_security_appliance_software
9.8.3.21
ciscoadaptive_security_appliance_software
9.8.3.26
ciscoadaptive_security_appliance_software
9.8.3.29
ciscoadaptive_security_appliance_software
9.8.4
ciscoadaptive_security_appliance_software
9.8.4.3
ciscoadaptive_security_appliance_software
9.8.4.7
ciscoadaptive_security_appliance_software
9.8.4.8
ciscoadaptive_security_appliance_software
9.8.4.10
ciscoadaptive_security_appliance_software
9.8.4.12
ciscoadaptive_security_appliance_software
9.8.4.15
ciscoadaptive_security_appliance_software
9.8.4.17
ciscoadaptive_security_appliance_software
9.8.4.20
ciscoadaptive_security_appliance_software
9.8.4.22
ciscoadaptive_security_appliance_software
9.8.4.25
ciscoadaptive_security_appliance_software
9.8.4.26
ciscoadaptive_security_appliance_software
9.8.4.29
ciscoadaptive_security_appliance_software
9.8.4.32
ciscoadaptive_security_appliance_software
9.8.4.33
ciscoadaptive_security_appliance_software
9.8.4.34
ciscoadaptive_security_appliance_software
9.8.4.35
ciscoadaptive_security_appliance_software
9.8.4.39
ciscoadaptive_security_appliance_software
9.8.4.40
ciscoadaptive_security_appliance_software
9.8.4.41
ciscoadaptive_security_appliance_software
9.8.4.43
ciscoadaptive_security_appliance_software
9.8.4.44
ciscoadaptive_security_appliance_software
9.8.4.45
ciscoadaptive_security_appliance_software
9.9.1
ciscoadaptive_security_appliance_software
9.9.1.2
ciscoadaptive_security_appliance_software
9.9.1.3
ciscoadaptive_security_appliance_software
9.9.1.4
ciscoadaptive_security_appliance_software
9.9.1.5
ciscoadaptive_security_appliance_software
9.9.2
ciscoadaptive_security_appliance_software
9.9.2.1
ciscoadaptive_security_appliance_software
9.9.2.9
ciscoadaptive_security_appliance_software
9.9.2.14
ciscoadaptive_security_appliance_software
9.9.2.18
ciscoadaptive_security_appliance_software
9.9.2.25
ciscoadaptive_security_appliance_software
9.9.2.27
ciscoadaptive_security_appliance_software
9.9.2.32
ciscoadaptive_security_appliance_software
9.9.2.36
ciscoadaptive_security_appliance_software
9.9.2.40
ciscoadaptive_security_appliance_software
9.9.2.47
ciscoadaptive_security_appliance_software
9.9.2.50
ciscoadaptive_security_appliance_software
9.9.2.52
ciscoadaptive_security_appliance_software
9.9.2.56
ciscoadaptive_security_appliance_software
9.9.2.59
ciscoadaptive_security_appliance_software
9.9.2.61
ciscoadaptive_security_appliance_software
9.9.2.66
ciscoadaptive_security_appliance_software
9.9.2.67
ciscoadaptive_security_appliance_software
9.9.2.74
ciscoadaptive_security_appliance_software
9.9.2.80
ciscoadaptive_security_appliance_software
9.9.2.83
ciscoadaptive_security_appliance_software
9.9.2.85
ciscoadaptive_security_appliance_software
9.10.1
ciscoadaptive_security_appliance_software
9.10.1.2
ciscoadaptive_security_appliance_software
9.10.1.7
ciscoadaptive_security_appliance_software
9.10.1.10
ciscoadaptive_security_appliance_software
9.10.1.11
ciscoadaptive_security_appliance_software
9.10.1.17
ciscoadaptive_security_appliance_software
9.10.1.22
ciscoadaptive_security_appliance_software
9.10.1.27
ciscoadaptive_security_appliance_software
9.10.1.30
ciscoadaptive_security_appliance_software
9.10.1.32
ciscoadaptive_security_appliance_software
9.10.1.37
ciscoadaptive_security_appliance_software
9.10.1.40
ciscoadaptive_security_appliance_software
9.10.1.42
ciscoadaptive_security_appliance_software
9.10.1.44
ciscoadaptive_security_appliance_software
9.12.1
ciscoadaptive_security_appliance_software
9.12.1.2
ciscoadaptive_security_appliance_software
9.12.1.3
ciscoadaptive_security_appliance_software
9.12.2
ciscoadaptive_security_appliance_software
9.12.2.1
ciscoadaptive_security_appliance_software
9.12.2.4
ciscoadaptive_security_appliance_software
9.12.2.5
ciscoadaptive_security_appliance_software
9.12.2.9
ciscoadaptive_security_appliance_software
9.12.3
ciscoadaptive_security_appliance_software
9.12.3.2
ciscoadaptive_security_appliance_software
9.12.3.7
ciscoadaptive_security_appliance_software
9.12.3.9
ciscoadaptive_security_appliance_software
9.12.3.12
ciscoadaptive_security_appliance_software
9.12.4
ciscoadaptive_security_appliance_software
9.12.4.2
ciscoadaptive_security_appliance_software
9.12.4.4
ciscoadaptive_security_appliance_software
9.12.4.7
ciscoadaptive_security_appliance_software
9.12.4.8
ciscoadaptive_security_appliance_software
9.12.4.10
ciscoadaptive_security_appliance_software
9.12.4.13
ciscoadaptive_security_appliance_software
9.12.4.18
ciscoadaptive_security_appliance_software
9.12.4.24
ciscoadaptive_security_appliance_software
9.12.4.26
ciscoadaptive_security_appliance_software
9.12.4.29
ciscoadaptive_security_appliance_software
9.12.4.30
ciscoadaptive_security_appliance_software
9.12.4.35
ciscoadaptive_security_appliance_software
9.12.4.37
ciscoadaptive_security_appliance_software
9.12.4.38
ciscoadaptive_security_appliance_software
9.12.4.39
ciscoadaptive_security_appliance_software
9.13.1
ciscoadaptive_security_appliance_software
9.13.1.2
ciscoadaptive_security_appliance_software
9.13.1.7
ciscoadaptive_security_appliance_software
9.13.1.10
ciscoadaptive_security_appliance_software
9.13.1.12
ciscoadaptive_security_appliance_software
9.13.1.13
ciscoadaptive_security_appliance_software
9.13.1.16
ciscoadaptive_security_appliance_software
9.13.1.19
ciscoadaptive_security_appliance_software
9.13.1.21
ciscoadaptive_security_appliance_software
9.14.1
ciscoadaptive_security_appliance_software
9.14.1.6
ciscoadaptive_security_appliance_software
9.14.1.10
ciscoadaptive_security_appliance_software
9.14.1.15
ciscoadaptive_security_appliance_software
9.14.1.19
ciscoadaptive_security_appliance_software
9.14.1.30
ciscoadaptive_security_appliance_software
9.14.2
ciscoadaptive_security_appliance_software
9.14.2.4
ciscoadaptive_security_appliance_software
9.14.2.8
ciscoadaptive_security_appliance_software
9.14.2.13
ciscoadaptive_security_appliance_software
9.14.2.15
ciscoadaptive_security_appliance_software
9.14.3
ciscoadaptive_security_appliance_software
9.14.3.1
ciscoadaptive_security_appliance_software
9.14.3.9
ciscoadaptive_security_appliance_software
9.14.3.11
ciscoadaptive_security_appliance_software
9.14.3.13
ciscoadaptive_security_appliance_software
9.14.3.15
ciscoadaptive_security_appliance_software
9.14.3.18
ciscoadaptive_security_appliance_software
9.14.4
ciscoadaptive_security_appliance_software
9.14.4.6
ciscoadaptive_security_appliance_software
9.15.1
ciscoadaptive_security_appliance_software
9.15.1.1
ciscoadaptive_security_appliance_software
9.15.1.7
ciscoadaptive_security_appliance_software
9.15.1.10
ciscoadaptive_security_appliance_software
9.15.1.15
ciscoadaptive_security_appliance_software
9.15.1.16
ciscoadaptive_security_appliance_software
9.15.1.17
ciscoadaptive_security_appliance_software
9.15.1.21
ciscoadaptive_security_appliance_software
9.16.1
ciscoadaptive_security_appliance_software
9.16.1.28
ciscoadaptive_security_appliance_software
9.16.2
ciscoadaptive_security_appliance_software
9.16.2.3
ciscoadaptive_security_appliance_software
9.16.2.7
ciscoadaptive_security_appliance_software
9.16.2.11
ciscoadaptive_security_appliance_software
9.16.2.13
ciscoadaptive_security_appliance_software
9.16.2.14
ciscoadaptive_security_appliance_software
9.17.1
ciscoadaptive_security_appliance_software
9.17.1.7
ciscofirepower_threat_defense
6.1.0
ciscofirepower_threat_defense
6.1.0.1
ciscofirepower_threat_defense
6.1.0.2
ciscofirepower_threat_defense
6.1.0.3
ciscofirepower_threat_defense
6.1.0.4
ciscofirepower_threat_defense
6.1.0.5
ciscofirepower_threat_defense
6.1.0.6
ciscofirepower_threat_defense
6.1.0.7
ciscofirepower_threat_defense
6.2.0
ciscofirepower_threat_defense
6.2.0.1
ciscofirepower_threat_defense
6.2.0.2
ciscofirepower_threat_defense
6.2.0.3
ciscofirepower_threat_defense
6.2.0.4
ciscofirepower_threat_defense
6.2.0.5
ciscofirepower_threat_defense
6.2.0.6
ciscofirepower_threat_defense
6.2.1
ciscofirepower_threat_defense
6.2.2
ciscofirepower_threat_defense
6.2.2.1
ciscofirepower_threat_defense
6.2.2.2
ciscofirepower_threat_defense
6.2.2.3
ciscofirepower_threat_defense
6.2.2.4
ciscofirepower_threat_defense
6.2.2.5
ciscofirepower_threat_defense
6.2.3
ciscofirepower_threat_defense
6.2.3.1
ciscofirepower_threat_defense
6.2.3.2
ciscofirepower_threat_defense
6.2.3.3
ciscofirepower_threat_defense
6.2.3.4
ciscofirepower_threat_defense
6.2.3.5
ciscofirepower_threat_defense
6.2.3.6
ciscofirepower_threat_defense
6.2.3.7
ciscofirepower_threat_defense
6.2.3.8
ciscofirepower_threat_defense
6.2.3.9
ciscofirepower_threat_defense
6.2.3.10
ciscofirepower_threat_defense
6.2.3.11
ciscofirepower_threat_defense
6.2.3.12
ciscofirepower_threat_defense
6.2.3.13
ciscofirepower_threat_defense
6.2.3.14
ciscofirepower_threat_defense
6.2.3.15
ciscofirepower_threat_defense
6.2.3.16
ciscofirepower_threat_defense
6.2.3.17
ciscofirepower_threat_defense
6.2.3.18
ciscofirepower_threat_defense
6.3.0
ciscofirepower_threat_defense
6.3.0.1
ciscofirepower_threat_defense
6.3.0.2
ciscofirepower_threat_defense
6.3.0.3
ciscofirepower_threat_defense
6.3.0.4
ciscofirepower_threat_defense
6.3.0.5
ciscofirepower_threat_defense
6.4.0
ciscofirepower_threat_defense
6.4.0.1
ciscofirepower_threat_defense
6.4.0.2
ciscofirepower_threat_defense
6.4.0.3
ciscofirepower_threat_defense
6.4.0.4
ciscofirepower_threat_defense
6.4.0.5
ciscofirepower_threat_defense
6.4.0.6
ciscofirepower_threat_defense
6.4.0.7
ciscofirepower_threat_defense
6.4.0.8
ciscofirepower_threat_defense
6.4.0.9
ciscofirepower_threat_defense
6.4.0.10
ciscofirepower_threat_defense
6.4.0.11
ciscofirepower_threat_defense
6.4.0.12
ciscofirepower_threat_defense
6.4.0.13
ciscofirepower_threat_defense
6.4.0.14
ciscofirepower_threat_defense
6.5.0
ciscofirepower_threat_defense
6.5.0.1
ciscofirepower_threat_defense
6.5.0.2
ciscofirepower_threat_defense
6.5.0.3
ciscofirepower_threat_defense
6.5.0.4
ciscofirepower_threat_defense
6.5.0.5
ciscofirepower_threat_defense
6.6.0
ciscofirepower_threat_defense
6.6.0.1
ciscofirepower_threat_defense
6.6.1
ciscofirepower_threat_defense
6.6.3
ciscofirepower_threat_defense
6.6.4
ciscofirepower_threat_defense
6.6.5
ciscofirepower_threat_defense
6.6.5.1
ciscofirepower_threat_defense
6.6.5.2
ciscofirepower_threat_defense
6.7.0
ciscofirepower_threat_defense
6.7.0.1
ciscofirepower_threat_defense
6.7.0.2
ciscofirepower_threat_defense
6.7.0.3
ciscofirepower_threat_defense
7.0.0
ciscofirepower_threat_defense
7.0.0.1
ciscofirepower_threat_defense
7.0.1
ciscofirepower_threat_defense
7.0.1.1
ciscofirepower_threat_defense
7.1.0
ciscofirepower_threat_defense
7.1.0.1
ciscofirepower_threat_defense
7.1.0.2
𝑥
= Vulnerable software versions