Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.

Project Subscriptions

Vendors Products
800m Integrated Services Router Subscribe
807 Industrial Integrated Services Router Subscribe
812 3g Integrated Services Router Subscribe
812 Cifi Integrated Services Router Subscribe
819 Hardened Dual Radio 802.11n Wifi Integrated Services Router Subscribe
819 Hardened Integrated Services Router Subscribe
829 Industrial Integrated Services Router Subscribe
860vae-w Integrated Services Router Subscribe
861 Integrated Services Router Subscribe
861w Integrated Services Router Subscribe
866vae Integrated Services Router Subscribe
867 Integrated Services Router Subscribe
867vae Integrated Services Router Subscribe
880-voice Integrated Services Router Subscribe
880 3g Integrated Services Router Subscribe
881-cube Integrated Services Router Subscribe
881 3g Integrated Services Router Subscribe
881 Integrated Services Router Subscribe
881w Integrated Services Router Subscribe
886 Integrated Services Router Subscribe
886va-cube Integrated Services Router Subscribe
886va-w Integrated Services Router Subscribe
886va Integrated Services Router Subscribe
886vag 3g Integrated Services Router Subscribe
887 Integrated Services Router Subscribe
887v Integrated Services Router Subscribe
887va-cube Integrated Services Router Subscribe
887va-w Integrated Services Router Subscribe
887va Integrated Services Router Subscribe
887vag 3g Integrated Services Router Subscribe
887vam-w Integrated Services Router Subscribe
887vamg 3g Integrated Services Router Subscribe
888-cube Integrated Services Router Subscribe
888 Integrated Services Router Subscribe
888e-cube Integrated Services Router Subscribe
888e Integrated Services Router Subscribe
888eg 3g Integrated Services Router Subscribe
888w Integrated Services Router Subscribe
891-24x Integrated Services Router Subscribe
891 Integrated Services Router Subscribe
891w Integrated Services Router Subscribe
892 Integrated Services Router Subscribe
892f-cube Integrated Services Router Subscribe
892w Integrated Services Router Subscribe
Cgr1000 Compute Module Subscribe
Cgr 1000 Subscribe
Cgr 1120 Subscribe
Cgr 1240 Subscribe
Ic3000 Industrial Compute Gateway Subscribe
Ie-4000-16gt4g-e Industrial Ethernet Switch Subscribe
Ie-4000-16t4g-e Industrial Ethernet Switch Subscribe
Ie-4000-4gc4gp4g-e Industrial Ethernet Switch Subscribe
Ie-4000-4gs8gp4g-e Industrial Ethernet Switch Subscribe
Ie-4000-4s8p4g-e Industrial Ethernet Switch Subscribe
Ie-4000-4t4p4g-e Industrial Ethernet Switch Subscribe
Ie-4000-4tc4g-e Industrial Ethernet Switch Subscribe
Ie-4000-8gs4g-e Industrial Ethernet Switch Subscribe
Ie-4000-8gt4g-e Industrial Ethernet Switch Subscribe
Ie-4000-8gt8gp4g-e Industrial Ethernet Switch Subscribe
Ie-4000-8s4g-e Industrial Ethernet Switch Subscribe
Ie-4000-8t4g-e Industrial Ethernet Switch Subscribe
Ie-4010-16s12p Industrial Ethernet Switch Subscribe
Ie-4010-4s24p Industrial Ethernet Switch Subscribe
Ir510 Operating System Subscribe
Ir510 Wpan Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-25975 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-06T16:23:50.620Z

Reserved: 2021-11-02T00:00:00

Link: CVE-2022-20725

cve-icon Vulnrichment

Updated: 2024-08-03T02:24:49.219Z

cve-icon NVD

Status : Modified

Published: 2022-04-15T15:15:13.510

Modified: 2024-11-21T06:43:25.270

Link: CVE-2022-20725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses