CVE-2022-20773 is a critical vulnerability in Cisco Umbrella Virtual Appliances (VA) stemming from a static SSH host key. This flaw allows an unauthenticated, remote attacker to perform a man-in-the-middle attack on SSH connections, potentially leading to the theft of administrator credentials, configuration changes, or VA reloads. With a CVSS score of 8.1 (High), the attack requires high complexity but has severe impacts on confidentiality, integrity, and availability. While SSH is not enabled by default, there is no evidence of active exploitation, nor are there public exploit codes or Metasploit modules available. However, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.2CPE matchmatch criteria | cpe:2.3:a:cisco:umbrella_virtual_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.