Description
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
Published: 2022-04-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-25977 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
History

No history.

Subscriptions

Cisco Cgr1000 Compute Module Ic3000 Industrial Compute Gateway Ios Ios Xe Ir510 Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-09-16T19:30:51.918Z

Reserved: 2021-11-02T00:00:00.000Z

Link: CVE-2022-20727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-15T15:15:13.613

Modified: 2024-11-21T06:43:25.583

Link: CVE-2022-20727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses