CVE-2022-20866 is a high-severity vulnerability affecting Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, allowing an unauthenticated, remote attacker to retrieve an RSA private key due to a logic error in hardware-based cryptography. This vulnerability, exploitable via a Lenstra side-channel attack, could enable an attacker to impersonate devices or decrypt traffic. The CVSS score is 7.5 (High), indicating a low attack complexity and high confidentiality impact. While not actively exploited or having public exploit code, it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.16.0, < 9.16.3.19CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.17.0, < 9.17.1.13CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.18.0, < 9.18.2CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.4CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 7.1.0, < 7.2.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.