Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-20773

19
FAUCET Score

CVE-2022-20773 is a critical vulnerability in Cisco Umbrella Virtual Appliances (VA) stemming from a static SSH host key. This flaw allows an unauthenticated, remote attacker to perform a man-in-the-middle attack on SSH connections, potentially leading to the theft of administrator credentials, configuration changes, or VA reloads. With a CVSS score of 8.1 (High), the attack requires high complexity but has severe impacts on confidentiality, integrity, and availability. While SSH is not enabled by default, there is no evidence of active exploitation, nor are there public exploit codes or Metasploit modules available. However, the vulnerability has garnered some community discussion and media coverage, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.2CPE matchmatch criteria
cpe:2.3:a:cisco:umbrella_virtual_appliance:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.13%
Probability of exploitation in next 30 days
EPSS Percentile
63.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0113 is in the 25th percentile among its peer group of 8,920 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

ciscovendor investigatingvia nvd_reference
View patch

References

tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-uva-static-key-6RQTRs4c
Vendor Advisory