CVE-2022-20649 is a critical vulnerability in Cisco RCM for StarOS Software, allowing unauthenticated, remote attackers to achieve root-level remote code execution due to an incorrectly enabled debug mode. This vulnerability carries a CVSS score of 8.1 (HIGH) due to its network attack vector, high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. While Cisco has released patches and no public exploit code is available, the vulnerability has garnered significant community attention and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco Redundancy Configuration Manager | 2021.01.0, 2021.02.0, 21.10.0, 21.10.1, 21.10.2, 21.10.3, 21.10.4, 21.10.5, 21.10.6, 21.11.0, 21.11.1, 21.11.10, 21.11.11, 21.11.12, 21.11.13, 21.11.14, 21.11.15, 21.11.16, 21.11.17, 21.11.18, 21.11.19, 21.11.2, 21.11.20, 21.11.21, 21.11.3, 21.11.4, 21.11.5, 21.11.6, 21.11.7, 21.11.8, 21.11.9, 21.12.0, 21.12.10, 21.12.11, 21.12.12, 21.12.13, 21.12.14, 21.12.15, 21.12.16, 21.12.17, 21.12.18, 21.12.19, 21.12.2, 21.12.20, 21.12.21, 21.12.22, 21.12.3, 21.12.4, 21.12.5, 21.12.6, 21.12.7, 21.12.8, 21.12.9, 21.13.0, 21.13.1, 21.13.10, 21.13.11, 21.13.12, 21.13.13, 21.13.14, 21.13.15, 21.13.16, 21.13.17, 21.13.18, 21.13.19, 21.13.2, 21.13.20, 21.13.21, 21.13.3, 21.13.4, 21.13.5, 21.13.6, 21.13.7, 21.13.8, 21.13.9, 21.14.0, 21.14.1, 21.14.10, 21.14.11, 21.14.12, 21.14.16, 21.14.17, 21.14.18, 21.14.19, 21.14.2, 21.14.20, 21.14.22, 21.14.23, 21.14.3, 21.14.4, 21.14.5, 21.14.6, 21.14.7, 21.14.8, 21.14.9, 21.14.RH0, 21.14.a0, 21.14.a5, 21.14.b12, 21.14.b13, 21.14.b14, 21.14.b15, 21.14.b16, 21.14.b17, 21.14.b18, 21.14.b19, 21.14.b20, 21.14.b21, 21.14.b22, 21.14.c2, 21.14.c3, 21.15.0, 21.15.1, 21.15.10, 21.15.11, 21.15.12, 21.15.13, 21.15.14, 21.15.15, 21.15.16, 21.15.17, 21.15.18, 21.15.19, 21.15.2, 21.15.20, 21.15.21, 21.15.22, 21.15.23, 21.15.24, 21.15.25, 21.15.26, 21.15.27, 21.15.28, 21.15.29, 21.15.3, 21.15.30, 21.15.32, 21.15.33, 21.15.36, 21.15.37, 21.15.39, 21.15.4, 21.15.40, 21.15.41, 21.15.43, 21.15.45, 21.15.46, 21.15.47, 21.15.48, 21.15.5, 21.15.51, 21.15.52, 21.15.53, 21.15.54, 21.15.55, 21.15.57, 21.15.58, 21.15.59, 21.15.6, 21.15.60, 21.15.7, 21.15.8, 21.15.9, 21.16.0, 21.16.1, 21.16.10, 21.16.2, 21.16.3, 21.16.4, 21.16.5, 21.16.6, 21.16.7, 21.16.8, 21.16.9, 21.16.c0, 21.16.c1, 21.16.c10, 21.16.c11, 21.16.c12, 21.16.c13, 21.16.c14, 21.16.c15, 21.16.c16, 21.16.c17, 21.16.c2, 21.16.c3, 21.16.c4, 21.16.c5, 21.16.c6, 21.16.c7, 21.16.c8, 21.16.c9, 21.16.d0, 21.16.d1, 21.17.0, 21.17.1, 21.17.10, 21.17.11, 21.17.13, 21.17.14, 21.17.15, 21.17.16, 21.17.17, 21.17.18, 21.17.19, 21.17.2, 21.17.3, 21.17.4, 21.17.5, 21.17.6, 21.17.7, 21.17.8, 21.17.9, 21.18.0, 21.18.1, 21.18.11, 21.18.12, 21.18.13, 21.18.14, 21.18.15, 21.18.16, 21.18.17, 21.18.18, 21.18.19, 21.18.2, 21.18.20, 21.18.21, 21.18.22, 21.18.23, 21.18.24, 21.18.3, 21.18.4, 21.18.5, 21.18.6, 21.18.7, 21.18.8, 21.18.9, 21.19.0, 21.19.1, 21.19.10, 21.19.11, 21.19.2, 21.19.3, 21.19.4, 21.19.5, 21.19.6, 21.19.7, 21.19.8, 21.19.9, 21.19.n1, 21.19.n10, 21.19.n11, 21.19.n12, 21.19.n13, 21.19.n14, 21.19.n2, 21.19.n3, 21.19.n4, 21.19.n5, 21.19.n6, 21.19.n7, 21.19.n8, 21.19.n9, 21.20.0, 21.20.1, 21.20.10, 21.20.11, 21.20.12, 21.20.13, 21.20.14, 21.20.15, 21.20.16, 21.20.17, 21.20.18, 21.20.19, 21.20.2, 21.20.20, 21.20.21, 21.20.22, 21.20.23, 21.20.24, 21.20.25, 21.20.26, 21.20.27, 21.20.28, 21.20.3, 21.20.4, 21.20.5, 21.20.6, 21.20.7, 21.20.8, 21.20.9, 21.20.SV1, 21.20.SV2, 21.20.SV3, 21.20.SV5, 21.20.UV0, 21.20.c22, 21.20.k6, 21.20.k7, 21.20.k8, 21.20.p9, 21.20.u8, 21.21.0, 21.21.1, 21.21.2, 21.21.3, 21.21.KS2, 21.22.0, 21.22.1, 21.22.10, 21.22.11, 21.22.2, 21.22.3, 21.22.4, 21.22.5, 21.22.6, 21.22.7, 21.22.8, 21.22.9, 21.22.n2, 21.22.n3, 21.22.n4, 21.22.n5, 21.22.ua0, 21.22.ua2, 21.22.ua3, 21.22.ua5, 21.22.uj3, 21.23.0, 21.23.1, 21.23.10, 21.23.11, 21.23.12, 21.23.2, 21.23.3, 21.23.4, 21.23.5, 21.23.6, 21.23.7, 21.23.8, 21.23.9, 21.23.b2, 21.23.b3, 21.23.n6, 21.23.n7, 21.24.0, 21.24.1, 21.24.2, 21.25.0, 21.25.1, 21.25.3, 21.4.0, 21.4.1, 21.4.10, 21.4.11, 21.4.12, 21.4.13, 21.4.14, 21.4.15, 21.4.16, 21.4.17, 21.4.2, 21.4.3, 21.4.4, 21.4.5, 21.4.6, 21.4.7, 21.4.8, 21.4.9, 21.5.0, 21.5.1, 21.5.10, 21.5.11, 21.5.12, 21.5.13, 21.5.14, 21.5.15, 21.5.16, 21.5.17, 21.5.19, 21.5.2, 21.5.20, 21.5.21, 21.5.22, 21.5.23, 21.5.24, 21.5.25, 21.5.26, 21.5.27, 21.5.28, 21.5.29, 21.5.3, 21.5.30, 21.5.4, 21.5.5, 21.5.6, 21.5.7, 21.5.8, 21.5.9, 21.6.0, 21.6.1, 21.6.10, 21.6.11, 21.6.12, 21.6.13, 21.6.14, 21.6.15, 21.6.2, 21.6.3, 21.6.4, 21.6.5, 21.6.6, 21.6.7, 21.6.8, 21.6.9, 21.6.b13, 21.6.b14, 21.6.b15, 21.6.b16, 21.6.b17, 21.6.b18, 21.6.b19, 21.6.b20, 21.6.b21, 21.6.b22, 21.6.b23, 21.6.b24, 21.6.b25, 21.6.b26, 21.7.0, 21.7.1, 21.7.10, 21.7.11, 21.7.12, 21.7.13, 21.7.2, 21.7.3, 21.7.4, 21.7.5, 21.7.6, 21.7.7, 21.7.8, 21.7.9, 21.8.0, 21.8.1, 21.8.10, 21.8.11, 21.8.12, 21.8.2, 21.8.3, 21.8.4, 21.8.5, 21.8.6, 21.8.7, 21.8.8, 21.8.9, 21.8.ca1, 21.9.0, 21.9.1, 21.9.10, 21.9.11, 21.9.12, 21.9.13, 21.9.2, 21.9.3, 21.9.4, 21.9.5, 21.9.6, 21.9.7, 21.9.8, 21.9.9, 5.1.15, 6.10.0, 6.11.0, 6.11.1, 6.12.0, 6.13.0, 6.13.EY1, 6.13.EY2, 6.14.0, 6.14.2, 6.2.5, 6.2.b14, 6.2.b15, 6.2.b16, 6.2.b17, 6.2.b4, 6.2.b5, 6.2.b6, 6.4.0, 6.5.0, 6.6.6, 6.6.7, 6.7.0, 6.8.1, 6.9.2, 6.9.5, 6.9.7, 6.9.8CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.