CVE-2022-20622
Cisco Embedded Wireless Controller with Catalyst Access Points IP Flood Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device may experience a performance degradation in traffic processing or high CPU usage prior to the unexpected reload. This vulnerability is due to improper rate limiting of IP packets to the management interface. An attacker could exploit this vulnerability by sending a steady stream of IP traffic at a high rate to the management interface of the affected device. A successful exploit could allow the attacker to cause the device to reload.
Una vulnerabilidad en el procesamiento de paquetes de entrada IP del software Cisco Embedded Wireless Controller with Catalyst Access Points podría permitir a un atacante remoto no autenticado hacer que el dispositivo sea recargado inesperadamente, causando una condición de denegación de servicio (DoS). El dispositivo puede experimentar una degradación del rendimiento en el procesamiento del tráfico o un alto uso de la CPU antes de la recarga no esperada. Esta vulnerabilidad es debido a una limitación inapropiada de la velocidad de los paquetes IP a la interfaz de administración. Un atacante podría aprovechar esta vulnerabilidad mediante el envío de un flujo constante de tráfico IP a una velocidad elevada a la interfaz de administración del dispositivo afectado. Una explotación con éxito podría permitir al atacante causar una recarga del dispositivo
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-11-02 CVE Reserved
- 2022-04-15 CVE Published
- 2024-11-06 CVE Updated
- 2024-11-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Aironet Access Point Software Search vendor "Cisco" for product "Aironet Access Point Software" | >= 17.3 < 17.3.4 Search vendor "Cisco" for product "Aironet Access Point Software" and version " >= 17.3 < 17.3.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Aironet Access Point Software Search vendor "Cisco" for product "Aironet Access Point Software" | >= 17.4 < 17.6.1 Search vendor "Cisco" for product "Aironet Access Point Software" and version " >= 17.4 < 17.6.1" | - |
Affected
|