PT-2022-6638 · Cisco · Cisco Network Convergence System (Ncs) 4000 Series+1
Published
2022-09-14
·
Updated
2024-11-18
·
CVE-2022-20845
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Network Convergence System (NCS) 4000 Series (affected versions not specified)
Description
The issue is related to the TL1 function of the Cisco Network Convergence System (NCS) 4000 Series, which is associated with uncontrolled memory allocation. An attacker could exploit this by connecting to the device, authenticating, and issuing TL1 commands, potentially causing the TL1 process to consume large amounts of memory. When the memory reaches a threshold, the Resource Monitor process will begin to restart or shutdown the top five consumers of memory, resulting in a denial of service.
Recommendations
For the Cisco Network Convergence System (NCS) 4000 Series, update to a version that includes the software updates released by Cisco to address this issue.
As a temporary workaround, consider restricting access to the TL1 function to minimize the risk of exploitation.
There are no other workarounds that address this issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr
Cisco Network Convergence System (Ncs) 4000 Series