Cisco ASA/FTD Observable Discrepancy (CVE-2022-20866)

high Tenable OT Security Plugin ID 505547

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following conditions may be observed on an affected device: This vulnerability will apply to approximately 5 percent of the RSA keys on a device that uses hardware-based cryptography, which is expected to be a small number of keys. An attacker must obtain a significant amount of ciphertext that was encrypted using the targeted RSA key before the attack can be successful.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?a31f6d9e

Plugin Details

Severity: High

ID: 505547

File Name: tenable_ot_cisco_CVE-2022-20866.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/20/2026

Updated: 7/20/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software, cpe:/o:cisco:firepower_threat_defense

Required KB Items: Tenable.ot/Cisco

Patch Publication Date: 8/10/2022

Vulnerability Publication Date: 8/10/2022

Reference Information

CVE: CVE-2022-20866

CWE: 203