PT-2022-2303 · Cisco · Cisco Sd-Wan Vedge Routers

Published

2022-04-13

·

Updated

2023-05-22

·

CVE-2022-20717

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN vEdge Routers (affected versions not specified)
Description The issue is related to insufficient memory management in the NETCONF process of Cisco SD-WAN vEdge Routers, which can lead to an uncontrolled memory consumption. An attacker could exploit this by sending large amounts of malicious traffic to an affected device, potentially causing the device to run out of memory and resulting in a denial of service (DoS) condition. This could allow the attacker to cause the device to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2022-02488
CVE-2022-20717

Affected Products

Cisco Sd-Wan Vedge Routers