Versio.io

CVE-2022-20697

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 15-04-2022 05:15
Last modified: - 26-04-2022 05:54
Total changes: - 2

Description

A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
None
Privileges required
Changed
Scope
None
User interaction
8.6
Base score
3.9
4.0
Exploitability score
Impact score
 

Verification logic

OR
vendor=cisco AND product=ios AND version=15.1\(3\)svr1
vendor=cisco AND product=ios AND version=15.1\(3\)svr2
vendor=cisco AND product=ios AND version=15.1\(3\)svr3
vendor=cisco AND product=ios AND version=15.1\(3\)svs
vendor=cisco AND product=ios AND version=15.1\(3\)svs1
vendor=cisco AND product=ios AND version=15.1\(3\)svt1
vendor=cisco AND product=ios AND version=15.1\(3\)svt2
vendor=cisco AND product=ios AND version=15.1\(3\)svt3
vendor=cisco AND product=ios AND version=15.1\(3\)svu1
vendor=cisco AND product=ios AND version=15.1\(3\)svu2
vendor=cisco AND product=ios AND version=15.1\(3\)svu10
vendor=cisco AND product=ios AND version=15.1\(3\)svv1
vendor=cisco AND product=ios AND version=15.2\(7\)e3
vendor=cisco AND product=ios AND version=15.2\(7\)e3a
vendor=cisco AND product=ios AND version=15.2\(7\)e3k
vendor=cisco AND product=ios AND version=15.2\(7\)e4
vendor=cisco AND product=ios AND version=15.2\(8\)e
vendor=cisco AND product=ios AND version=15.2\(234k\)e
vendor=cisco AND product=ios AND version=15.3\(3\)jk100
vendor=cisco AND product=ios AND version=15.3\(3\)jpj8
vendor=cisco AND product=ios AND version=15.9\(3\)m2
vendor=cisco AND product=ios AND version=15.9\(3\)m2a
vendor=cisco AND product=ios AND version=15.9\(3\)m3
vendor=cisco AND product=ios AND version=15.9\(3\)m3a
vendor=cisco AND product=ios AND version=15.9\(3\)m3b
vendor=cisco AND product=ios AND version=15.9\(3\)m4
vendor=cisco AND product=ios_xe AND version=3.11.3ae
vendor=cisco AND product=ios_xe AND version=3.11.3e
vendor=cisco AND product=ios_xe AND version=3.11.4e
 

Reference

 


Keywords

NVD

 

CVE-2022-20697

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.