目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2022-20866— Cisco Firepower Threat Defense 和Cisco Adaptive Security Appliances Software 安全漏洞

CVSS 7.4 · High EPSS 8.92% · P93
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-20866の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
ソース: NVD (National Vulnerability Database)
脆弱性説明
A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following conditions may be observed on an affected device: This vulnerability will apply to approximately 5 percent of the RSA keys on a device that is running a vulnerable release of Cisco ASA Software or Cisco FTD Software; not all RSA keys are expected to be affected due to mathematical calculations applied to the RSA key. The RSA key could be valid but have specific characteristics that make it vulnerable to the potential leak of the RSA private key. If an attacker obtains the RSA private key, they could use the key to impersonate a device that is running Cisco ASA Software or Cisco FTD Software or to decrypt the device traffic. See the Indicators of Compromise section for more information on the detection of this type of RSA key. The RSA key could be malformed and invalid. A malformed RSA key is not functional, and a TLS client connection to a device that is running Cisco ASA Software or Cisco FTD Software that uses the malformed RSA key will result in a TLS signature failure, which means a vulnerable software release created an invalid RSA signature that failed verification. If an attacker obtains the RSA private key, they could use the key to impersonate a device that is running Cisco ASA Software or Cisco FTD Software or to decrypt the device traffic.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
通过差异性导致的信息暴露
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Cisco Firepower Threat Defense 和Cisco Adaptive Security Appliances Software 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Cisco Firepower Threat Defense(FTD)和Cisco Adaptive Security Appliances Software(ASA Software)都是美国思科(Cisco)公司的产品。Cisco Firepower Threat Defense是一套提供下一代防火墙服务的统一软件。Cisco Adaptive Security Appliances Software是一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。 Cisco Adap
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
CiscoCisco Adaptive Security Appliance (ASA) Software n/a -

II. CVE-2022-20866の公開POC

#POC説明ソースリンクShenlongリンク
1RSA Key Checker for CVE-2022-20866https://github.com/CiscoPSIRT/CVE-2022-20866POC詳細
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-20866のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Cisco · 2022-08-10 · 11 CVEs total

CVE-2022-208279.0 CRITICALCisco Small Business RV Series Routers Vulnerabilities
CVE-2022-208429.0 CRITICALCisco Small Business RV Series Routers Vulnerabilities
CVE-2022-208419.0 CRITICALCisco Small Business RV Series Routers Vulnerabilities
CVE-2022-207927.8 HIGHClamAV AntiVirus 缓冲区错误漏洞
CVE-2022-208166.5 MEDIUMCisco Unified Communications Manager Arbitrary File Deletion Vulnerability
CVE-2022-208696.1 MEDIUMCisco BroadWorks Application Delivery Platform Software Cross-Site Scripting Vulnerability
CVE-2022-208205.4 MEDIUMCisco Webex Meetings Web Interface Vulnerabilities
CVE-2022-208525.4 MEDIUMCisco Webex Meetings Web Interface Vulnerabilities
CVE-2022-209144.9 MEDIUMCisco Identity Services Engine Sensitive Information Disclosure Vulnerability
CVE-2022-207134.3 MEDIUMCisco Adaptive Security Appliances Software 跨站脚本漏洞

IV. 関連脆弱性

V. CVE-2022-20866へのコメント

まだコメントはありません


コメントを残す