CVE-2022-20727 describes multiple vulnerabilities within the Cisco IOx application hosting environment, impacting various Cisco platforms including CGR1000 Compute Module, IC3000 Industrial Compute Gateway, IOS, IOS XE, and IR510 Operating System. With a CVSS score of 6.7 (Medium), these flaws allow highly privileged local attackers to achieve arbitrary command injection, code execution, unauthenticated application installation, or cross-site scripting. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.15.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:cgr1000_compute_module:*:*:*:*:*:*:*:* | ||
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:cisco:ic3000_industrial_compute_gateway:*:*:*:*:*:*:*:* | ||
< 6.5.9CPE matchmatch criteria | cpe:2.3:a:cisco:ir510_operating_system:*:*:*:*:*:*:*:* | ||
15.2\(5\)e1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(5\)e1:*:*:*:*:*:*:* | ||
15.2\(6\)e0aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(6\)e0a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.