HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2022-20742

CVSS 7.4v3.1pub. 2022-05-03upd. 2026-08-11

A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker in a man-in-the-middle position could exploit this vulnerability by intercepting a sufficient number of encrypted messages across an affected IPsec IKEv2 VPN tunnel and then using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to decrypt, read, modify, and re-encrypt data that is transmitted across an affected IPsec IKEv2 VPN tunnel.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Cisco Adaptive Security Appliance Software

    OS
    Cisco
    9.17.0 – 9.17.1.7 (excl.)< 9.12.4.389.13.0 – 9.14.4 (excl.)9.15.0 – 9.15.1.21 (excl.)9.16.0 – 9.16.2.14 (excl.)
  • Cisco Secure Firewall Threat Defense

    APP
    Cisco
    7.1.06.5.0 – 6.6.5.2 (excl.)7.0.0 – 7.0.2 (excl.)< 6.4.0.15
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2024-20329CRITICAL9.9PL ✓same product

RCE w podsystemie SSH Cisco ASA — wykonanie poleceń jako root

CVE-2024-20412CRITICAL9.3PL ✓same product

Cisco FTD: statyczne konta z zakodowanymi hasłami umożliwiają nieautoryzowany dostęp

CVE-2020-3125CRITICAL9.8PL ✓same product

Cisco ASA — obejście uwierzytelniania Kerberos w VPN (Auth Bypass)