CVE-2022-20693 is a command injection vulnerability in the web UI of Cisco IOS XE Software, affecting various Cisco devices. An authenticated, remote attacker can exploit this flaw by sending crafted input to the web UI API, leading to arbitrary command execution with root privileges on the underlying operating system. The vulnerability has a CVSS score of 7.2 (High), indicating a high impact on confidentiality, integrity, and availability, with low attack complexity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.15.1xbsCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.15.1xbs:*:*:*:*:*:*:* | ||
3.15.2xbsCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.15.2xbs:*:*:*:*:*:*:* | ||
16.12.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.12.1:*:*:*:*:*:*:* | ||
16.12.1aCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.12.1a:*:*:*:*:*:*:* | ||
16.12.1cCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.12.1c:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.