CVE-2022-20651
Cisco Adaptive Security Device Manager Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is due to the storage of unencrypted credentials in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view the credentials of other users of the shared device.
Una vulnerabilidad en el componente de registro de Cisco Adaptive Security Device Manager (ASDM) podría permitir a un atacante local autentificado ver información sensible en texto claro en un sistema afectado. Cisco ADSM debe ser desplegado en un entorno de estación de trabajo compartida para que este problema sea explotado. Esta vulnerabilidad se debe al almacenamiento de credenciales sin cifrar en determinados registros. Un atacante podría aprovechar esta vulnerabilidad accediendo a los registros de un sistema afectado. Una explotación exitosa podría permitir al atacante ver las credenciales de otros usuarios del dispositivo compartido
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-02 CVE Reserved
- 2022-06-22 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-01 CVE Updated
- 2024-11-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.rapid7.com/blog/post/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software | 2024-11-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Adaptive Security Device Manager Search vendor "Cisco" for product "Adaptive Security Device Manager" | >= 7.15.1 < 7.17.1 Search vendor "Cisco" for product "Adaptive Security Device Manager" and version " >= 7.15.1 < 7.17.1" | - |
Affected
|