---
id: CVE-2022-20773
title: >-
  A vulnerability in the key-based SSH authentication mechanism of Cisco
  Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote
  attacker to impersonate a VA
summary: >-
  A vulnerability in the key-based SSH authentication mechanism of Cisco
  Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote
  attacker to impersonate a VA. This vulnerability is due to the presence of a
  static SSH host ke…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-321
  - CWE-798
published: '2022-04-21'
updated: '2026-06-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-20773'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uva-static-key-6RQTRs4c
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uva-static-key-6RQTRs4c
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01182
epssPercentile: 0.66414
ingestedAt: '2026-06-29T13:24:33.493Z'
---

## Overview

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a man-in-the-middle attack on an SSH connection to the Umbrella VA. A successful exploit could allow the attacker to learn the administrator credentials, change configurations, or reload the VA. Note: SSH is not enabled by default on the Umbrella VA.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
