PT-2021-7074 · Cisco · Cisco Ios+2
Published
2021-11-02
·
Updated
2022-05-16
·
CVE-2022-20731
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Catalyst Digital Building Series Switches (affected versions not specified)
Cisco Catalyst Micro Switches (affected versions not specified)
Description
The issue affects Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches, allowing an attacker to execute persistent code at boot time or permanently prevent the device from booting, resulting in a permanent denial of service (DoS) condition. The vulnerability is related to deficiencies in the security mechanisms of the Cisco IOS bootloader. An attacker could exploit this vulnerability to execute arbitrary code remotely.
Recommendations
For Cisco Catalyst Digital Building Series Switches, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Cisco Catalyst Micro Switches, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Catalyst Digital Building Series Switches
Cisco Catalyst Micro Switches
Cisco Ios