Vulnerability Description
A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 16.9.6 |
| Cisco | Catalyst 8000V Edge | - |
| Cisco | Cloud Services Router 1000V | - |
| Cisco | 1100-4G Integrated Services Router | - |
| Cisco | 1100-6G Integrated Services Router | - |
| Cisco | 1101 Integrated Services Router | - |
| Cisco | 1109 Integrated Services Router | - |
| Cisco | 1111X Integrated Services Router | - |
| Cisco | 111X Integrated Services Router | - |
| Cisco | 1120 Integrated Services Router | - |
| Cisco | 1131 Integrated Services Router | - |
| Cisco | 1160 Integrated Services Router | - |
| Cisco | 4221 Integrated Services Router | - |
| Cisco | 4331 Integrated Services Router | - |
| Cisco | 4431 Integrated Services Router | - |
| Cisco | 4461 Integrated Services Router | - |
| Cisco | Asr 1001-X | - |
| Cisco | Asr 1002-X | - |
| Cisco | Catalyst 8300-1N1S-4T2X | - |
| Cisco | Catalyst 8300-1N1S-6T | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aVendor Advisory
FAQ
What is CVE-2022-20678?
CVE-2022-20678 is a vulnerability with a CVSS score of 8.6 (HIGH). A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) conditio...
How severe is CVE-2022-20678?
CVE-2022-20678 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-20678?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Catalyst 8000V Edge, Cisco Cloud Services Router 1000V, Cisco 1100-4G Integrated Services Router, Cisco 1100-6G Integrated Services Router.