Versio.io

CVE-2022-20678

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 15-04-2022 05:15
Last modified: - 25-04-2022 05:28
Total changes: - 2

Description

A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
7.5
Base score
3.9
3.6
Exploitability score
Impact score
 

Verification logic

AND
OR
vendor=cisco AND product=ios_xe AND version=16.9.6
vendor=cisco AND product=ios_xe AND version=16.12.4
vendor=cisco AND product=ios_xe AND version=16.12.5
vendor=cisco AND product=ios_xe AND version=17.3.3
OR
vendor=cisco AND product=catalyst_8000v_edge AND version=-
vendor=cisco AND product=cloud_services_router_1000v AND version=-
vendor=cisco AND product=asr_1001-x AND version=-
vendor=cisco AND product=asr_1002-x AND version=-
vendor=cisco AND product=catalyst_8300-1n1s-4t2x AND version=-
vendor=cisco AND product=catalyst_8300-1n1s-6t AND version=-
vendor=cisco AND product=catalyst_8300-2n2s-4t2x AND version=-
vendor=cisco AND product=catalyst_8300-2n2s-6t AND version=-
vendor=cisco AND product=catalyst_8500 AND version=-
vendor=cisco AND product=catalyst_8500-4qc AND version=-
vendor=cisco AND product=catalyst_8500l AND version=-
vendor=cisco AND product=isr_1100-4g AND version=-
vendor=cisco AND product=isr_1100-6g AND version=-
vendor=cisco AND product=isr_1101 AND version=-
vendor=cisco AND product=isr_1109 AND version=-
vendor=cisco AND product=isr_1111x AND version=-
vendor=cisco AND product=isr_111x AND version=-
vendor=cisco AND product=isr_1120 AND version=-
vendor=cisco AND product=isr_1131 AND version=-
vendor=cisco AND product=isr_1160 AND version=-
vendor=cisco AND product=isr_4221 AND version=-
vendor=cisco AND product=isr_4331 AND version=-
vendor=cisco AND product=isr_4431 AND version=-
vendor=cisco AND product=isr_4461 AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2022-20678

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.