PT-2022-6322 · Cisco · Cisco Ios Xe+1

Published

2022-09-28

·

Updated

2023-07-21

·

CVE-2022-20919

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified)
Description The issue is related to insufficient input validation during the processing of Common Industrial Protocol (CIP) packets, which could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. An attacker could exploit this by sending a malformed CIP packet to an affected device. The exploitation could lead to the affected device reloading, causing a DoS condition.
Recommendations For Cisco IOS Software, update to a version that includes the fix for this issue. For Cisco IOS XE Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CIP protocol to minimize the risk of exploitation.

Fix

DoS

Improper Handling of Exceptional Conditions

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-00900
CVE-2022-20919

Affected Products

Cisco Ios
Cisco Ios Xe