Cyber Resilience

CVE-2022-20777

CriticalPublic PoC

Published: 04 May 2022

Published
04 May 2022
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0304 87.0th percentile
Risk Priority 22 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-20777 is a critical-severity Improper Access Control (CWE-284) vulnerability in Cisco Enterprise Nfv Infrastructure Software. Its CVSS base score is 9.9 (Critical).

Operationally, ranked in the top 13.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

Cisco Enterprise NFV Infrastructure Software (NFVIS) contains multiple vulnerabilities that permit an attacker to escape a guest virtual machine to the underlying host, execute commands with root privileges, or leak host system data back into the guest. The issues are tracked under CVE-2022-20777 and carry a CVSS 3.1 score of 9.9, reflecting network attack vector, low complexity, and a changed scope that allows the compromise to cross VM boundaries.

An authenticated user inside a guest VM can leverage the flaws to gain full control of the host system, resulting in complete loss of confidentiality, integrity, and availability on the NFVIS platform. Because the vulnerabilities affect the virtualization layer itself, successful exploitation provides a direct path from tenant workloads to the underlying infrastructure without requiring additional privileges on the host.

The Cisco Security Advisory cisco-sa-NFVIS-MUL-7DySRX9 and the associated GitHub advisory detail the affected releases and available fixes. Exploitation probability reached a peak of 0.1167 in December 2025 before receding to the current value of 0.0304, indicating a period of elevated interest after disclosure.

EU & UK References

Vulnerability details

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host…

more

to the VM. For more information about these vulnerabilities, see the Details section of this advisory.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

cisco
enterprise nfv infrastructure software
≤ 4.7.1

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-284

The access control policy and procedures directly mandate and enforce proper access control mechanisms across the organization.

addresses: CWE-284

Device lock enforces restricted access until re-authentication, directly reducing unauthorized use of active sessions.

addresses: CWE-284

Supervision and review of access control activities directly detects and remediates improper access configurations or usages.

addresses: CWE-284

Explicitly identifying and documenting actions permitted without identification or authentication enforces proper access control boundaries by defining justified exceptions.

addresses: CWE-284

By automatically labeling outputs with security attributes, the control supports attribute-based enforcement and reduces exploitability of improper access control weaknesses.

addresses: CWE-284

Associating and retaining security attributes with data directly supports enforcement of access control decisions across storage, processing, and transmission.

addresses: CWE-284

Requiring prior authorization for each remote access type prevents improper access control over remote connections.

addresses: CWE-284

Requiring authorization of wireless access before allowing connections enforces proper access control for this access method.

References