Cisco Email Secure Appliance SQLi via Web UI (CVE-2022-20867)
CVE-2022-20867 Published on November 4, 2022
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.
Vulnerability Analysis
CVE-2022-20867 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a SQL Injection Vulnerability?
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
CVE-2022-20867 has been classified to as a SQL Injection vulnerability or weakness.
Products Associated with CVE-2022-20867
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-20867 are published in Cisco Email Security Appliance:
Affected Versions
Cisco Secure Email:- Version 13.0.0-392 is affected.
- Version 13.5.1-277 is affected.
- Version 12.5.0-066 is affected.
- Version 14.0.0-698 is affected.
- Version 14.2.0-620 is affected.
- Version 12.0.1-011 is affected.
- Version 12.5.0-636 is affected.
- Version 12.5.0-658 is affected.
- Version 12.5.0-678 is affected.
- Version 12.5.0-670 is affected.
- Version 13.0.0-277 is affected.
- Version 13.6.2-078 is affected.
- Version 13.8.1-068 is affected.
- Version 13.8.1-074 is affected.
- Version 12.8.1-002 is affected.
- Version 14.0.0-404 is affected.
- Version 14.1.0-223 is affected.
- Version 14.1.0-227 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.