Improper Resource Locking in Cisco Systems, Inc products - CVE-2022-20678
Published: April 14, 2022
Vulnerability identifier: #VU62317
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-20678
CWE-ID: CWE-413
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco IOS XE
Cisco 1000 Series Integrated Services Routers
4000 Series Integrated Services Routers
ASR 1001-X Router
ASR 1002-X Router
Catalyst 8300 Series Routers
Catalyst 8500 Series Routers
Catalyst 8000V Edge Software
Cloud Services Router 1000V Series
Cisco IOS XE
Cisco 1000 Series Integrated Services Routers
4000 Series Integrated Services Routers
ASR 1001-X Router
ASR 1002-X Router
Catalyst 8300 Series Routers
Catalyst 8500 Series Routers
Catalyst 8000V Edge Software
Cloud Services Router 1000V Series
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the incorrect handling of certain TCP segments in the AppNav-XE feature. A remote attacker can send a stream of crafted TCP traffic and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.