Description
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Published: 2022-04-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-25975 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 800m Integrated Services Router 807 Industrial Integrated Services Router 812 3g Integrated Services Router 812 Cifi Integrated Services Router 819 Hardened Dual Radio 802.11n Wifi Integrated Services Router 819 Hardened Integrated Services Router 829 Industrial Integrated Services Router 860vae-w Integrated Services Router 861 Integrated Services Router 861w Integrated Services Router 866vae Integrated Services Router 867 Integrated Services Router 867vae Integrated Services Router 880-voice Integrated Services Router 880 3g Integrated Services Router 881-cube Integrated Services Router 881 3g Integrated Services Router 881 Integrated Services Router 881w Integrated Services Router 886 Integrated Services Router 886va-cube Integrated Services Router 886va-w Integrated Services Router 886va Integrated Services Router 886vag 3g Integrated Services Router 887 Integrated Services Router 887v Integrated Services Router 887va-cube Integrated Services Router 887va-w Integrated Services Router 887va Integrated Services Router 887vag 3g Integrated Services Router 887vam-w Integrated Services Router 887vamg 3g Integrated Services Router 888-cube Integrated Services Router 888 Integrated Services Router 888e-cube Integrated Services Router 888e Integrated Services Router 888eg 3g Integrated Services Router 888w Integrated Services Router 891-24x Integrated Services Router 891 Integrated Services Router 891w Integrated Services Router 892 Integrated Services Router 892f-cube Integrated Services Router 892w Integrated Services Router Cgr1000 Compute Module Cgr 1000 Cgr 1120 Cgr 1240 Ic3000 Industrial Compute Gateway Ie-4000-16gt4g-e Industrial Ethernet Switch Ie-4000-16t4g-e Industrial Ethernet Switch Ie-4000-4gc4gp4g-e Industrial Ethernet Switch Ie-4000-4gs8gp4g-e Industrial Ethernet Switch Ie-4000-4s8p4g-e Industrial Ethernet Switch Ie-4000-4t4p4g-e Industrial Ethernet Switch Ie-4000-4tc4g-e Industrial Ethernet Switch Ie-4000-8gs4g-e Industrial Ethernet Switch Ie-4000-8gt4g-e Industrial Ethernet Switch Ie-4000-8gt8gp4g-e Industrial Ethernet Switch Ie-4000-8s4g-e Industrial Ethernet Switch Ie-4000-8t4g-e Industrial Ethernet Switch Ie-4010-16s12p Industrial Ethernet Switch Ie-4010-4s24p Industrial Ethernet Switch Ios Ios Xe Ir510 Operating System Ir510 Wpan
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-06T16:23:50.620Z

Reserved: 2021-11-02T00:00:00.000Z

Link: CVE-2022-20725

cve-icon Vulnrichment

Updated: 2024-08-03T02:24:49.219Z

cve-icon NVD

Status : Modified

Published: 2022-04-15T15:15:13.510

Modified: 2024-11-21T06:43:25.270

Link: CVE-2022-20725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses