Lucene search

K
cveCiscoCVE-2022-20762
HistoryApr 06, 2022 - 7:15 p.m.

CVE-2022-20762

2022-04-0619:15:08
CWE-284
cisco
web.nvd.nist.gov
79
cve-2022-20762
vulnerability
privilege escalation
cisco
ultra cloud core
subscriber microservices infrastructure
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to insufficient access control in the affected CLI. An attacker could exploit this vulnerability by authenticating as a CEE ConfD CLI user and executing a specific CLI command. A successful exploit could allow an attacker to access privileged containers with root privileges.

Affected configurations

Nvd
Node
ciscoultra_cloud_core_-_subscriber_microservices_infrastructureRange2020.02.2.02020.02.2.47
OR
ciscoultra_cloud_core_-_subscriber_microservices_infrastructureRange2020.02.6.02020.02.7.07
VendorProductVersionCPE
ciscoultra_cloud_core_-_subscriber_microservices_infrastructure*cpe:2.3:a:cisco:ultra_cloud_core_-_subscriber_microservices_infrastructure:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%