CVE-2022-20656
MEDIUMDescription
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system. This vulnerability is due to insufficient input validation of the HTTPS URL by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request that contains directory traversal character sequences to an affected device. A successful exploit could allow the attacker to write arbitrary files to the host system. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Is your site exposed to CVE-2022-20656?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
| cisco | evolved_programmable_network_manager |
References
Frequently Asked Questions
What is CVE-2022-20656? +
How severe is CVE-2022-20656? +
What products are affected by CVE-2022-20656? +
How do I check if I'm vulnerable to CVE-2022-20656? +
Related Vulnerabilities
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the …
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs …
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template …
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. …
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller …