Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20717

Опубликовано: 15 апр. 2022
Источник: nvd
CVSS3: 5.5
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:cisco:sd-wan_vedge_router:*:*:*:*:*:*:*:*
Версия до 20.6 (включая)
cpe:2.3:a:cisco:sd-wan_vedge_router:20.7:*:*:*:*:*:*:*

Одно из

cpe:2.3:h:cisco:1100_integrated_services_router:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_110:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_1100:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_210:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_2100:-:*:*:*:*:*:*:*
cpe:2.3:h:citrix:sd-wan_5100:-:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-789
CWE-770

Связанные уязвимости

CVSS3: 5.5
github
почти 4 года назад

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость реализации протокола NETCONF микропрограммного обеспечения маршрутизаторов Cisco SD-WAN vEdge, позволяющая нарушителю вызвать отказ в обслуживании или вызвать аварийное завершение работы приложения

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-789
CWE-770