#VU66750 Stack-based buffer overflow in Cisco NX-OS - CVE-2022-20824
Published: August 24, 2022
Cisco NX-OS
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the Cisco Discovery Protocol feature. A remote unauthenticated attacker can send a malicious Cisco Discovery Protocol packet to an affected device, trigger a stack-based buffer overflow and execute arbitrary code on the target system with root privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable device.
Remediation
External links
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cdp-dos-ce-wWvPucC9
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb70210
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74493
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74494
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74495
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74496
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74497
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74498
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwb74513