Denial of service when handling SNMP connections in Cisco ESA, WSA and Secure Email and Web Manager



Published: 2022-04-06
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2022-20675
CWE-ID CWE-248
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Cisco Email Security Appliance
Server applications / IDS/IPS systems, Firewalls and proxy servers

Cisco Web Security Appliance
Server applications / IDS/IPS systems, Firewalls and proxy servers

Cisco Secure Email and Web Manager
Server applications / Other server solutions

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Uncaught Exception

EUVDB-ID: #VU61942

Risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-20675

CWE-ID: CWE-248 - Uncaught Exception

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect handling of connection requests sent to port 199/tcp. A remote non-authenticated attacker can connect to port 199/tcp and crash the SNMP service.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Cisco Email Security Appliance: 13.0.1 - 14.0

Cisco Secure Email and Web Manager: 12.5 - 14.1

Cisco Web Security Appliance: 12.0.1 268 - 14.0.2

External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ESA-SNMP-JLAJksWK
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa06167
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa07400
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa08629


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###