CVE-2022-20868 (CNNVD-202211-1897)
中文标题:
多款Cisco产品信任管理问题漏洞
英文标题:
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secur...
漏洞描述
中文描述:
Cisco Email Security Appliance(ESA)等都是美国思科(Cisco)公司的产品。Cisco Email Security Appliance是一个电子邮件安全设备。Cisco Secure Web Appliance是一个应用程序。Cisco Secure Email是思科安全电子邮件(前身为电子邮件安全)为您的电子邮件提供最佳保护,使其免受网络威胁。 Cisco多款产品存在信任管理问题漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
英文描述:
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Secure Web Appliance | 11.8.0-414 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:11.8.0-414:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 11.8.1-023 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:11.8.1-023:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 11.8.3-018 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:11.8.3-018:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 11.8.3-021 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:11.8.3-021:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 12.0.1-268 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:12.0.1-268:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 12.0.3-007 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:12.0.3-007:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 12.5.2-007 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:12.5.2-007:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 12.5.1-011 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:12.5.1-011:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 12.5.4-005 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:12.5.4-005:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 14.5.0-498 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:14.5.0-498:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Web Appliance | 14.0.2-012 | - | - |
cpe:2.3:a:cisco:cisco_secure_web_appliance:14.0.2-012:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email | 13.0.0-392 | - | - |
cpe:2.3:a:cisco:cisco_secure_email:13.0.0-392:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email | 13.5.1-277 | - | - |
cpe:2.3:a:cisco:cisco_secure_email:13.5.1-277:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email | 14.0.0-698 | - | - |
cpe:2.3:a:cisco:cisco_secure_email:14.0.0-698:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email | 14.2.0-620 | - | - |
cpe:2.3:a:cisco:cisco_secure_email:14.2.0-620:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.0.0-452 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.0.0-452:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.0.1-011 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.0.1-011:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.5.0-636 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.5.0-636:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.5.0-658 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.5.0-658:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.5.0-678 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.5.0-678:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.5.0-670 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.5.0-670:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 13.0.0-277 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:13.0.0-277:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 13.6.2-078 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:13.6.2-078:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 13.8.1-068 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:13.8.1-068:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 13.8.1-074 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:13.8.1-074:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 12.8.1-002 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:12.8.1-002:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 14.0.0-404 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:14.0.0-404:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 14.1.0-223 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:14.1.0-223:*:*:*:*:*:*:*
|
| Cisco | Cisco Secure Email and Web Manager | 14.1.0-227 | - | - |
cpe:2.3:a:cisco:cisco_secure_email_and_web_manager:14.1.0-227:*:*:*:*:*:*:*
|
| cisco | asyncos | * | - | - |
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
|
| cisco | asyncos | 14.5 | - | - |
cpe:2.3:o:cisco:asyncos:14.5:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-20868 |
2025-11-11 15:21:15 | 2025-11-11 07:37:15 |
| NVD | nvd_CVE-2022-20868 |
2025-11-11 14:58:27 | 2025-11-11 07:45:32 |
| CNNVD | cnnvd_CNNVD-202211-1897 |
2025-11-11 15:11:02 | 2025-11-11 07:57:37 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信任管理问题
- cnnvd_id: 未提取 -> CNNVD-202211-1897
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 29 -> 31
- data_sources: ['cve'] -> ['cve', 'nvd']