#VU62337 Resource exhaustion in Cisco Systems, Inc products - CVE-2022-20692
Published: April 14, 2022
Vulnerability identifier: #VU62337
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-20692
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco IOS XE
Catalyst 3850 Series Switches
Catalyst 9200 Series Switches
Catalyst 9300 Series Switches
Catalyst 9400 Series Switches
Catalyst 9500 Series Switches
Catalyst 9500H Series Switches
Catalyst 9600 Series Switches
Cisco IOS XE
Catalyst 3850 Series Switches
Catalyst 9200 Series Switches
Catalyst 9300 Series Switches
Catalyst 9400 Series Switches
Catalyst 9500 Series Switches
Catalyst 9500H Series Switches
Catalyst 9600 Series Switches
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the NETCONF over SSH feature. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.