CVE-2022-20725

high-risk
Published 2022-04-15

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.

Do I need to act?

-
0.76% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10 Medium
NETWORK / LOW complexity

Affected Products (20)

Cgr1000 Compute Module
Ic3000 Industrial Compute Gateway
Ir510 Operating System
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios
Ios

Affected Vendors

57
/ 100
high-risk
Severity 21/34 · High
Exploitability 3/34 · Minimal
Exposure 33/34 · Critical