CVE-2022-20665 is a privilege escalation vulnerability in the Command Line Interface (CLI) of Cisco StarOS, affecting products like Cisco ASR 5500, ASR 5700, and Ultra Cloud Core. This flaw, stemming from insufficient input validation, allows an authenticated local attacker to execute arbitrary code as the root user by sending crafted CLI commands. Rated Medium severity with a CVSS score of 6.7, exploitation requires valid administrative credentials and has high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.22.n6CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* | ||
>= 21.23.0, < 21.23.n7CPE matchmatch criteria | cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.