PT-2022-2310 · Snort+1 · Snort+1

Uri Katz

·

Published

2022-01-19

·

Updated

2025-06-24

·

CVE-2022-20685

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Snort (affected versions not specified)
Description The issue is caused by an integer overflow while processing Modbus traffic, allowing a remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending crafted Modbus traffic through an affected device, potentially causing the Snort process to hang and stopping traffic inspection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-02496
CVE-2022-20685

Affected Products

Cisco Ios Xe
Snort