4.6

CVE-2022-20864

A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xe Rom Monitor Version-
   CiscoCatalyst 3650 Version-
   CiscoCatalyst 3650-12x48fd-e Version-
   CiscoCatalyst 3650-12x48fd-l Version-
   CiscoCatalyst 3650-12x48fd-s Version-
   CiscoCatalyst 3650-12x48uq Version-
   CiscoCatalyst 3650-12x48uq-e Version-
   CiscoCatalyst 3650-12x48uq-l Version-
   CiscoCatalyst 3650-12x48uq-s Version-
   CiscoCatalyst 3650-12x48ur Version-
   CiscoCatalyst 3650-12x48ur-e Version-
   CiscoCatalyst 3650-12x48ur-l Version-
   CiscoCatalyst 3650-12x48ur-s Version-
   CiscoCatalyst 3650-12x48uz Version-
   CiscoCatalyst 3650-12x48uz-e Version-
   CiscoCatalyst 3650-12x48uz-l Version-
   CiscoCatalyst 3650-12x48uz-s Version-
   CiscoCatalyst 3650-24pd Version-
   CiscoCatalyst 3650-24pd-e Version-
   CiscoCatalyst 3650-24pd-l Version-
   CiscoCatalyst 3650-24pd-s Version-
   CiscoCatalyst 3650-24pdm Version-
   CiscoCatalyst 3650-24pdm-e Version-
   CiscoCatalyst 3650-24pdm-l Version-
   CiscoCatalyst 3650-24pdm-s Version-
   CiscoCatalyst 3650-24ps-e Version-
   CiscoCatalyst 3650-24ps-l Version-
   CiscoCatalyst 3650-24ps-s Version-
   CiscoCatalyst 3650-24td-e Version-
   CiscoCatalyst 3650-24td-l Version-
   CiscoCatalyst 3650-24td-s Version-
   CiscoCatalyst 3650-24ts-e Version-
   CiscoCatalyst 3650-24ts-l Version-
   CiscoCatalyst 3650-24ts-s Version-
   CiscoCatalyst 3650-48fd-e Version-
   CiscoCatalyst 3650-48fd-l Version-
   CiscoCatalyst 3650-48fd-s Version-
   CiscoCatalyst 3650-48fq Version-
   CiscoCatalyst 3650-48fq-e Version-
   CiscoCatalyst 3650-48fq-l Version-
   CiscoCatalyst 3650-48fq-s Version-
   CiscoCatalyst 3650-48fqm Version-
   CiscoCatalyst 3650-48fqm-e Version-
   CiscoCatalyst 3650-48fqm-l Version-
   CiscoCatalyst 3650-48fqm-s Version-
   CiscoCatalyst 3650-48fs-e Version-
   CiscoCatalyst 3650-48fs-l Version-
   CiscoCatalyst 3650-48fs-s Version-
   CiscoCatalyst 3650-48pd-e Version-
   CiscoCatalyst 3650-48pd-l Version-
   CiscoCatalyst 3650-48pd-s Version-
   CiscoCatalyst 3650-48pq-e Version-
   CiscoCatalyst 3650-48pq-l Version-
   CiscoCatalyst 3650-48pq-s Version-
   CiscoCatalyst 3650-48ps-e Version-
   CiscoCatalyst 3650-48ps-l Version-
   CiscoCatalyst 3650-48ps-s Version-
   CiscoCatalyst 3650-48td-e Version-
   CiscoCatalyst 3650-48td-l Version-
   CiscoCatalyst 3650-48td-s Version-
   CiscoCatalyst 3650-48tq-e Version-
   CiscoCatalyst 3650-48tq-l Version-
   CiscoCatalyst 3650-48tq-s Version-
   CiscoCatalyst 3650-48ts-e Version-
   CiscoCatalyst 3650-48ts-l Version-
   CiscoCatalyst 3650-48ts-s Version-
   CiscoCatalyst 3650-8x24pd-e Version-
   CiscoCatalyst 3650-8x24pd-l Version-
   CiscoCatalyst 3650-8x24pd-s Version-
   CiscoCatalyst 3650-8x24uq Version-
   CiscoCatalyst 3650-8x24uq-e Version-
   CiscoCatalyst 3650-8x24uq-l Version-
   CiscoCatalyst 3650-8x24uq-s Version-
   CiscoCatalyst 3850 Version-
   CiscoCatalyst 3850-12s-e Version-
   CiscoCatalyst 3850-12s-s Version-
   CiscoCatalyst 3850-12x48u Version-
   CiscoCatalyst 3850-12xs-e Version-
   CiscoCatalyst 3850-12xs-s Version-
   CiscoCatalyst 3850-16xs-e Version-
   CiscoCatalyst 3850-16xs-s Version-
   CiscoCatalyst 3850-24p-e Version-
   CiscoCatalyst 3850-24p-l Version-
   CiscoCatalyst 3850-24p-s Version-
   CiscoCatalyst 3850-24pw-s Version-
   CiscoCatalyst 3850-24s-e Version-
   CiscoCatalyst 3850-24s-s Version-
   CiscoCatalyst 3850-24t-e Version-
   CiscoCatalyst 3850-24t-l Version-
   CiscoCatalyst 3850-24t-s Version-
   CiscoCatalyst 3850-24u Version-
   CiscoCatalyst 3850-24u-e Version-
   CiscoCatalyst 3850-24u-l Version-
   CiscoCatalyst 3850-24u-s Version-
   CiscoCatalyst 3850-24xs Version-
   CiscoCatalyst 3850-24xs-e Version-
   CiscoCatalyst 3850-24xs-s Version-
   CiscoCatalyst 3850-24xu Version-
   CiscoCatalyst 3850-24xu-e Version-
   CiscoCatalyst 3850-24xu-l Version-
   CiscoCatalyst 3850-24xu-s Version-
   CiscoCatalyst 3850-32xs-e Version-
   CiscoCatalyst 3850-32xs-s Version-
   CiscoCatalyst 3850-48f-e Version-
   CiscoCatalyst 3850-48f-l Version-
   CiscoCatalyst 3850-48f-s Version-
   CiscoCatalyst 3850-48p-e Version-
   CiscoCatalyst 3850-48p-l Version-
   CiscoCatalyst 3850-48p-s Version-
   CiscoCatalyst 3850-48pw-s Version-
   CiscoCatalyst 3850-48t-e Version-
   CiscoCatalyst 3850-48t-l Version-
   CiscoCatalyst 3850-48t-s Version-
   CiscoCatalyst 3850-48u Version-
   CiscoCatalyst 3850-48u-e Version-
   CiscoCatalyst 3850-48u-l Version-
   CiscoCatalyst 3850-48u-s Version-
   CiscoCatalyst 3850-48xs Version-
   CiscoCatalyst 3850-48xs-e Version-
   CiscoCatalyst 3850-48xs-f-e Version-
   CiscoCatalyst 3850-48xs-f-s Version-
   CiscoCatalyst 3850-48xs-s Version-
   CiscoCatalyst 3850-nm-2-40g Version-
   CiscoCatalyst 3850-nm-8-10g Version-
   CiscoCatalyst 9200 Version-
   CiscoCatalyst 9200cx Version-
   CiscoCatalyst 9200l Version-
   CiscoCatalyst 9300 Version-
   CiscoCatalyst 9300-24p-a Version-
   CiscoCatalyst 9300-24p-e Version-
   CiscoCatalyst 9300-24s-a Version-
   CiscoCatalyst 9300-24s-e Version-
   CiscoCatalyst 9300-24t-a Version-
   CiscoCatalyst 9300-24t-e Version-
   CiscoCatalyst 9300-24u-a Version-
   CiscoCatalyst 9300-24u-e Version-
   CiscoCatalyst 9300-24ux-a Version-
   CiscoCatalyst 9300-24ux-e Version-
   CiscoCatalyst 9300-48p-a Version-
   CiscoCatalyst 9300-48p-e Version-
   CiscoCatalyst 9300-48s-a Version-
   CiscoCatalyst 9300-48s-e Version-
   CiscoCatalyst 9300-48t-a Version-
   CiscoCatalyst 9300-48t-e Version-
   CiscoCatalyst 9300-48u-a Version-
   CiscoCatalyst 9300-48u-e Version-
   CiscoCatalyst 9300-48un-a Version-
   CiscoCatalyst 9300-48un-e Version-
   CiscoCatalyst 9300-48uxm-a Version-
   CiscoCatalyst 9300-48uxm-e Version-
   CiscoCatalyst 9300l Version-
   CiscoCatalyst 9300l-24p-4g-a Version-
   CiscoCatalyst 9300l-24p-4g-e Version-
   CiscoCatalyst 9300l-24p-4x-a Version-
   CiscoCatalyst 9300l-24p-4x-e Version-
   CiscoCatalyst 9300l-24t-4g-a Version-
   CiscoCatalyst 9300l-24t-4g-e Version-
   CiscoCatalyst 9300l-24t-4x-a Version-
   CiscoCatalyst 9300l-24t-4x-e Version-
   CiscoCatalyst 9300l-48p-4g-a Version-
   CiscoCatalyst 9300l-48p-4g-e Version-
   CiscoCatalyst 9300l-48p-4x-a Version-
   CiscoCatalyst 9300l-48p-4x-e Version-
   CiscoCatalyst 9300l-48t-4g-a Version-
   CiscoCatalyst 9300l-48t-4g-e Version-
   CiscoCatalyst 9300l-48t-4x-a Version-
   CiscoCatalyst 9300l-48t-4x-e Version-
   CiscoCatalyst 9300l Stack Version-
   CiscoCatalyst 9300lm Version-
   CiscoCatalyst 9300x Version-
   CiscoCatalyst 9400 Version-
   CiscoCatalyst 9407r Version-
   CiscoCatalyst 9410r Version-
   CiscoCatalyst 9500 Version-
   CiscoCatalyst 9500h Version-
   CiscoCatalyst 9600 Version-
   CiscoCatalyst 9600x Version-
   CiscoCatalyst C2928-24lt-c Version-
   CiscoCatalyst C2928-48tc-c Version-
   CiscoCatalyst C3850-12x48u-e Version-
   CiscoCatalyst C3850-12x48u-l Version-
   CiscoCatalyst C3850-12x48u-s Version-
   CiscoCatalyst C9200-24p Version-
   CiscoCatalyst C9200-24t Version-
   CiscoCatalyst C9200-48p Version-
   CiscoCatalyst C9200-48t Version-
   CiscoCatalyst C9200l-24p-4g Version-
   CiscoCatalyst C9200l-24p-4x Version-
   CiscoCatalyst C9200l-24pxg-2y Version-
   CiscoCatalyst C9200l-24pxg-4x Version-
   CiscoCatalyst C9200l-24t-4g Version-
   CiscoCatalyst C9200l-24t-4x Version-
   CiscoCatalyst C9200l-48p-4g Version-
   CiscoCatalyst C9200l-48p-4x Version-
   CiscoCatalyst C9200l-48pxg-2y Version-
   CiscoCatalyst C9200l-48pxg-4x Version-
   CiscoCatalyst C9200l-48t-4g Version-
   CiscoCatalyst C9200l-48t-4x Version-
   CiscoCatalyst C9300-24p Version-
   CiscoCatalyst C9300-24s Version-
   CiscoCatalyst C9300-24t Version-
   CiscoCatalyst C9300-24u Version-
   CiscoCatalyst C9300-24ux Version-
   CiscoCatalyst C9300-48p Version-
   CiscoCatalyst C9300-48s Version-
   CiscoCatalyst C9300-48t Version-
   CiscoCatalyst C9300-48u Version-
   CiscoCatalyst C9300-48un Version-
   CiscoCatalyst C9300-48uxm Version-
   CiscoCatalyst C9300l-24p-4g Version-
   CiscoCatalyst C9300l-24p-4x Version-
   CiscoCatalyst C9300l-24t-4g Version-
   CiscoCatalyst C9300l-24t-4x Version-
   CiscoCatalyst C9300l-48p-4g Version-
   CiscoCatalyst C9300l-48p-4x Version-
   CiscoCatalyst C9300l-48t-4g Version-
   CiscoCatalyst C9300l-48t-4x Version-
   CiscoCatalyst C9404r Version-
   CiscoCatalyst C9407r Version-
   CiscoCatalyst C9410r Version-
   CiscoCatalyst C9500-12q Version-
   CiscoCatalyst C9500-12q-a Version-
   CiscoCatalyst C9500-12q-e Version-
   CiscoCatalyst C9500-16x Version-
   CiscoCatalyst C9500-16x-a Version-
   CiscoCatalyst C9500-16x-e Version-
   CiscoCatalyst C9500-24q Version-
   CiscoCatalyst C9500-24q-a Version-
   CiscoCatalyst C9500-24q-e Version-
   CiscoCatalyst C9500-24y4c Version-
   CiscoCatalyst C9500-32c Version-
   CiscoCatalyst C9500-32qc Version-
   CiscoCatalyst C9500-40x Version-
   CiscoCatalyst C9500-40x-a Version-
   CiscoCatalyst C9500-40x-e Version-
   CiscoCatalyst C9500-48y4c Version-
   CiscoCatalyst C9600-lc-24c Version-
   CiscoCatalyst C9600-lc-48s Version-
   CiscoCatalyst C9600-lc-48tx Version-
   CiscoCatalyst C9600-lc-48yl Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.306
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
psirt@cisco.com 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.