CVE-2022-20944

A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerability is due to an improper check in the code function that manages the verification of the digital signatures of system image files during the initial boot process. An attacker could exploit this vulnerability by loading unsigned software on an affected device. A successful exploit could allow the attacker to boot a malicious software image or execute unsigned code and bypass the image verification check part of the boot process of the affected device. To exploit this vulnerability, the attacker needs either unauthenticated physical access to the device or privileged access to the root shell on the device. Note: In Cisco IOS XE Software releases 16.11.1 and later, root shell access is protected by the Consent Token mechanism. However, an attacker with level-15 privileges could easily downgrade the Cisco IOS XE Software running on a device to a release where root shell access is more readily available.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:catalyst_9200:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_9200cx:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_9200l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-24p:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-24t:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-48p:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-48t:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24p-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24p-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24pxg-2y:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24pxg-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24t-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24t-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48p-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48p-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48pxg-2y:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48pxg-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48t-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48t-4x:-:*:*:*:*:*:*:*

History

13 Oct 2022, 19:43

Type Values Removed Values Added
CWE CWE-347
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-cat-verify-D4NEQA6q - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-cat-verify-D4NEQA6q - Vendor Advisory
CPE cpe:2.3:h:cisco:catalyst_c9200l-48t-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24pxg-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-48p:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-48t:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48p-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24pxg-2y:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24p-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48t-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_9200cx:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48pxg-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48pxg-2y:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24t-4g:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_9200l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24t-4x:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-24t:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_9200:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-24p-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200l-48p-4x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_c9200-24p:-:*:*:*:*:*:*:*
First Time Cisco catalyst C9200l-48t-4x
Cisco catalyst C9200l-48p-4x
Cisco catalyst C9200l-24p-4g
Cisco catalyst C9200l-24p-4x
Cisco catalyst C9200l-48p-4g
Cisco catalyst C9200l-24pxg-4x
Cisco catalyst 9200l
Cisco catalyst C9200-24p
Cisco catalyst 9200cx
Cisco catalyst C9200l-48pxg-4x
Cisco catalyst C9200l-48pxg-2y
Cisco catalyst C9200-24t
Cisco catalyst C9200l-24t-4x
Cisco catalyst 9200
Cisco
Cisco catalyst C9200-48p
Cisco catalyst C9200l-24t-4g
Cisco catalyst C9200l-48t-4g
Cisco catalyst C9200-48t
Cisco catalyst C9200l-24pxg-2y
Cisco ios Xe

10 Oct 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-10 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-20944

Mitre link : CVE-2022-20944

CVE.ORG link : CVE-2022-20944


JSON object : View

Products Affected

cisco

  • catalyst_9200
  • catalyst_c9200l-24t-4x
  • catalyst_9200cx
  • catalyst_9200l
  • catalyst_c9200l-48t-4g
  • catalyst_c9200l-24t-4g
  • catalyst_c9200l-24p-4x
  • catalyst_c9200-24p
  • catalyst_c9200l-48p-4g
  • ios_xe
  • catalyst_c9200l-24pxg-4x
  • catalyst_c9200l-24pxg-2y
  • catalyst_c9200-48t
  • catalyst_c9200-24t
  • catalyst_c9200l-24p-4g
  • catalyst_c9200l-48pxg-4x
  • catalyst_c9200l-48p-4x
  • catalyst_c9200-48p
  • catalyst_c9200l-48t-4x
  • catalyst_c9200l-48pxg-2y
CWE
CWE-347

Improper Verification of Cryptographic Signature