Rewterz

Rewterz Threat Advisory – Cisco Firepower Threat Defense And Management Center (FMC) Software Vulnerabilities

November 18, 2022
Rewterz

Rewterz Threat Alert – Mirai Botnet – Active IOCs

November 18, 2022

Rewterz Threat Advisory – CVE-2022-20826 – Cisco Secure Firewalls Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-20826

Node.js is vulnerable to HTTP request smuggling, caused by the failure to correctly handle header fields that are not terminated with CLRF by the llhttp parser in the http module. A remote attacker could send a specially-crafted request to lead to HTTP Request Smuggling (HRS). An attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.

Impact

Security Bypass

Indicators Of Compromise

CVE

  • CVE-2022-20826

Affected Vendors

Cisco

Affected Products

  • Cisco Secure Firewall 3100 Series

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.