A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.
Conclusion & alert: CVE-2022-20934 is rated Low Risk (34.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.11%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-24 | 0.18% | 0.11% | -0.06% |
| 2 | 2025-11-21 | 0.11% | 0.18% | +0.06% |
| 3 | 2025-11-18 | — | 0.11% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.0 | 3.1 | MEDIUM |
|
0.8 | 5.2 | [email protected] |
| 6.7 | 3.1 | MEDIUM |
|
0.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | firepower_threat_defense | >= 6.1.0, <= 6.1.0.7 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.2.0, <= 6.2.0.6 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.2.2, <= 6.2.2.5 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.2.3, <= 6.2.3.18 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.3.0, <= 6.3.0.5 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.4.0, <= 6.4.0.15 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.5.0, <= 6.5.0.5 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 6.7.0, <= 6.7.0.3 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | >= 7.0.0, <= 7.0.4 | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.2.1 | cpe:2.3:a:cisco:firepower_threat_defense:6.2.1:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.0 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.0:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.0.1 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.0.1:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.1 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.1:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.3 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.3:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.4 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.4:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.5 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.5:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.5.1 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.5.1:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.5.2 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.5.2:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 6.6.7 | cpe:2.3:a:cisco:firepower_threat_defense:6.6.7:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 7.1.0.0 | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0.0:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 7.1.0.1 | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0.1:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 7.1.0.2 | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0.2:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 7.2.0 | cpe:2.3:a:cisco:firepower_threat_defense:7.2.0:*:*:*:*:*:*:* |
| cisco | firepower_threat_defense | 7.2.0.1 | cpe:2.3:a:cisco:firepower_threat_defense:7.2.0.1:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.1.147 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.1.147:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.1.160 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.1.160:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.2.51 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.2.51:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.2.178 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.2.178:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.3.84 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.3.84:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.3.86 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.3.86:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.3.97 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.3.97:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.95 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.95:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.117 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.117:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.140 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.140:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.169 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.169:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.175 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.175:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.178 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.178:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 1.1.4.179 | cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1.4.179:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.37 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.37:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.68 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.68:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.86 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.86:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.135 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.135:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.141 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.141:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.144 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.144:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.148 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.148:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.149 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.149:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.153 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.153:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.159 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.159:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.188 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.188:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.201 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.201:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.203 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.203:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.204 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.204:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.0.1.206 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.0.1.206:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.64 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.64:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.73 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.73:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.77 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.77:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.83 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.83:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.85 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.85:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.86 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.86:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.97 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.97:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.106 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.106:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.107 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.107:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.113 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.113:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.115 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.115:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.1.1.116 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.1.1.116:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.1.63 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.63:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.1.66 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.66:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.1.70 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.70:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.17 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.17:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.19 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.19:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.24 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.24:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.26 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.26:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.28 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.28:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.54 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.54:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.60 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.60:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.71 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.71:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.83 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.83:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.86 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.86:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.91 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.91:*:*:*:*:*:*:* |
| cisco | firepower_extensible_operating_system | 2.2.2.97 | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.97:*:*:*:*:*:*:* |