← Vulnerability feed

Vulnerability record · CVE-2022-20828 · published 24 June 2022

CVE-2022-20828: Cisco ASA FirePOWER CLI command injection allows root command execution

Cisco · Asa Firepower

Cisco FirePOWER Software for the ASA FirePOWER module mishandles undefined command parameters in its CLI parser, allowing crafted CLI commands or HTTPS requests to the management interface to inject commands. Because the injected commands run as root on the underlying operating system, the flaw gives full control of the module to an attacker who already holds administrative access to the ASA.

7.2 CVSS 3.1 High EPSS 49% · top 1.1% CWE-236 · CWE-236
7.2CVSS 3.1 base score, v2 9.0
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit this vulnerability, the attacker must have administrative access to the Cisco ASA. A user who has administrative access to a particular Cisco ASA is also expected to have administrative access to the ASA FirePOWER module that is hosted by that Cisco ASA.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw yields root command execution and public exploit code exists, but it requires prior administrative access to the ASA, limiting who can reach it.

What it is

Cisco FirePOWER Software for the ASA FirePOWER module mishandles undefined command parameters in its CLI parser, allowing crafted CLI commands or HTTPS requests to the management interface to inject commands. Because the injected commands run as root on the underlying operating system, the flaw gives full control of the module to an attacker who already holds administrative access to the ASA.

Impact

An attacker gains arbitrary command execution as root on the ASA FirePOWER module's underlying operating system, enabling full compromise of that module.

Attack surface

Reachable remotely over the network through the ASA FirePOWER CLI or the web-based management interface of the hosting ASA. Exploitation requires valid administrative access to the Cisco ASA; no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.49294, 98.8th percentile) and public references are tagged Exploit, indicating working exploit code is publicly available.

What to do

  • Apply the Cisco vendor advisory fix for the ASA FirePOWER module as the first action.
  • Restrict administrative access to the ASA and its FirePOWER module to trusted management networks and accounts.
  • Limit exposure of the ASA web-based management interface and CLI to trusted hosts.
  • Audit and reduce the number of accounts with administrative access to the ASA and hosted FirePOWER module.
  • Monitor for unexpected root-level activity on the FirePOWER module after administrative logins.

Detection

  • Review ASA and FirePOWER CLI command logs for crafted or malformed command parameters.
  • Monitor HTTPS requests to the ASA management interface for command-injection patterns.
  • Alert on unexpected root-level process or command execution on the FirePOWER module.
  • Correlate administrative logins with subsequent anomalous OS-level activity on the module.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-20828 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2022-20828), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.