Cisco ASA Trust Boundary Violation (CVE-2022-20826)

medium Tenable OT Security Plugin ID 506137

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?8388a793

Plugin Details

Severity: Medium

ID: 506137

File Name: tenable_ot_cisco_CVE-2022-20826.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software:9.17.1.10, cpe:/o:cisco:adaptive_security_appliance_software:9.17.1.13, cpe:/o:cisco:adaptive_security_appliance_software:9.17.1.9, cpe:/o:cisco:adaptive_security_appliance_software:9.17.1, cpe:/o:cisco:adaptive_security_appliance_software:9.18.1.3, cpe:/o:cisco:adaptive_security_appliance_software:9.18.1

Required KB Items: Tenable.ot/Cisco

Patch Publication Date: 11/15/2022

Vulnerability Publication Date: 11/15/2022

Reference Information

CVE: CVE-2022-20826

CWE: 501