CVE-2022-20724
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
- Affected products
- Cisco Iox, Cisco Ios, Cisco Ios Xe
- Cisco cgr1000 Compute Module
- All versions
- Cisco ic3000 Industrial Compute Gateway
- All versions
- Cisco Ios
- = 15.2\(5\)e1, 15.2\(5\)e2c, 15.2\(6\)e0a, 15.2\(6\)e1, 15.2\(6\)e2a, 15.2\(7\)e, 15.2\(7\)e0b, 15.2\(7\)e0s, 15.6\(1\)t1, 15.6\(1\)t2, 15.6\(1\)t3, 15.6\(2\)t, 15.6\(2\)t0a, 15.6\(2\)t1, 15.6\(2\)t2, 15.6\(2\)t3, 15.6\(3\)m, 15.6\(3\)m0a, 15.6\(3\)m1, 15.6\(3\)m1a, 15.6\(3\)m1b, 15.6\(3\)m2, 15.6\(3\)m2a, 15.6\(3\)m3, 15.6\(3\)m3a, 15.6\(3\)m4, 15.6\(3\)m5, 15.6\(3\)m6, 15.6\(3\)m6a, 15.6\(3\)m6b, 15.6\(3\)m7, 15.6\(3\)m8, 15.6\(3\)m9, 15.7\(3\)m, 15.7\(3\)m0a, 15.7\(3\)m1, 15.7\(3\)m2, 15.7\(3\)m3
- CVSS 2.0
- 7.6 HIGH
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-22, CWE-362
- NVD status
- Modified
- Published
- 2022-04-15
CVE-2022-20724 at NVD
No indexed exploits for CVE-2022-20724 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-20724 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.