// For flags

CVE-2022-20651

Cisco Adaptive Security Device Manager Information Disclosure Vulnerability

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device.

Una vulnerabilidad en el componente de registro de Cisco Adaptive Security Device Manager (ASDM) podría permitir a un atacante local autentificado ver información sensible en texto claro en un sistema afectado. Cisco ADSM debe ser desplegado en un entorno de estación de trabajo compartida para que este problema sea explotado. Esta vulnerabilidad se debe al almacenamiento de credenciales sin cifrar en determinados registros. Un atacante podría aprovechar esta vulnerabilidad accediendo a los registros de un sistema afectado. Una explotación exitosa podría permitir al atacante ver las credenciales de otros usuarios del dispositivo compartido

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2021-11-02 CVE Reserved
  • 2022-06-22 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-11-01 CVE Updated
  • 2024-11-01 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-532: Insertion of Sensitive Information into Log File
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Adaptive Security Device Manager
Search vendor "Cisco" for product "Adaptive Security Device Manager"
>= 7.15.1 < 7.17.1
Search vendor "Cisco" for product "Adaptive Security Device Manager" and version " >= 7.15.1 < 7.17.1"
-
Affected