Uncaught Exception in Cisco Systems, Inc products - CVE-2022-20675
Published: April 6, 2022
Vulnerability identifier: #VU61942
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20675
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of connection requests sent to port 199/tcp. A remote non-authenticated attacker can connect to port 199/tcp and crash the SNMP service.
Affected software
Cisco Web Security Appliance
Cisco Email Security Appliance
Cisco Secure Email and Web Manager
Cisco Email Security Appliance
Cisco Secure Email and Web Manager
How to mitigate CVE-2022-20675
Install updates from vendor's website.
Cisco Web Security Appliance - update to 14.0.2-012
Cisco Secure Email and Web Manager - update to 14.1.0-239
Cisco Email Security Appliance - update to 14.02.0-020
Cisco Secure Email and Web Manager - update to 14.1.0-239
Cisco Email Security Appliance - update to 14.02.0-020