CVE-2022-20742
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerability is due to an improper implementation of Galois/Counter Mode (GCM) ciphers. An attacker in a man-in-the-middle position could exploit this vulnerability by intercepting a sufficient number of encrypted messages across an affected IPsec IKEv2 VPN tunnel and then using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to decrypt, read, modify, and re-encrypt data that is transmitted across an affected IPsec IKEv2 VPN tunnel.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.13%
- CWE
- CWE-325
- Published
- 2022-05-03
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2020-15086 — Potential Remote Code Execution in TYPO3 with mediace extension
- CVE-2026-22863 — Deno node:crypto doesn't finalize cipher
- CVE-2020-15098 — Missing Required Cryptographic Step Leading to Sensitive Information Disclosure in TYPO3 CMS
- CVE-2025-30147 — ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve
- CVE-2018-5383 — Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
- CVE-2026-4601 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
- CVE-2023-46129 — xkeys Seal encryption used fixed key for all encryption
- CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices