Vulnerability record · CVE-2022-20828 · published 24 June 2022
CVE-2022-20828: Cisco ASA FirePOWER CLI command injection allows root command execution
Cisco · Asa Firepower
Cisco FirePOWER Software for the ASA FirePOWER module mishandles undefined command parameters in its CLI parser, allowing crafted CLI commands or HTTPS requests to the management interface to inject commands. Because the injected commands run as root on the underlying operating system, the flaw gives full control of the module to an attacker who already holds administrative access to the ASA.
Description
A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit this vulnerability, the attacker must have administrative access to the Cisco ASA. A user who has administrative access to a particular Cisco ASA is also expected to have administrative access to the ASA FirePOWER module that is hosted by that Cisco ASA.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields root command execution and public exploit code exists, but it requires prior administrative access to the ASA, limiting who can reach it.
What it is
Cisco FirePOWER Software for the ASA FirePOWER module mishandles undefined command parameters in its CLI parser, allowing crafted CLI commands or HTTPS requests to the management interface to inject commands. Because the injected commands run as root on the underlying operating system, the flaw gives full control of the module to an attacker who already holds administrative access to the ASA.
Impact
An attacker gains arbitrary command execution as root on the ASA FirePOWER module's underlying operating system, enabling full compromise of that module.
Attack surface
Reachable remotely over the network through the ASA FirePOWER CLI or the web-based management interface of the hosting ASA. Exploitation requires valid administrative access to the Cisco ASA; no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.49294, 98.8th percentile) and public references are tagged Exploit, indicating working exploit code is publicly available.
What to do
- Apply the Cisco vendor advisory fix for the ASA FirePOWER module as the first action.
- Restrict administrative access to the ASA and its FirePOWER module to trusted management networks and accounts.
- Limit exposure of the ASA web-based management interface and CLI to trusted hosts.
- Audit and reduce the number of accounts with administrative access to the ASA and hosted FirePOWER module.
- Monitor for unexpected root-level activity on the FirePOWER module after administrative logins.
Detection
- Review ASA and FirePOWER CLI command logs for crafted or malformed command parameters.
- Monitor HTTPS requests to the ASA management interface for command-injection patterns.
- Alert on unexpected root-level process or command execution on the FirePOWER module.
- Correlate administrative logins with subsequent anomalous OS-level activity on the module.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-20828 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2022-20828), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.