Out-of-bounds read in Cisco Systems, Inc products - CVE-2022-20823

 

Out-of-bounds read in Cisco Systems, Inc products - CVE-2022-20823

Published: August 24, 2022


Vulnerability identifier: #VU66749
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20823
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when processing OSPFv3 packets. A remote attacker can send specially crafted OSPFv3 link-state advertisement (LSA) packets to an affected device, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

Nexus 9000 Series Fabric Switches
Cisco Nexus 9000 Series Switches
Nexus 7000 Series Switches
Nexus 6000 Series Switches
Nexus 5600 Platform Switches
Nexus 5500 Platform Switches
Cisco Nexus 3000 Series Switches
Cisco NX-OS

How to mitigate CVE-2022-20823

Install updates from vendor's website.

Cisco NX-OS - update to 8.2.8

External References

Related Security Bulletins