Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20051

Опубликовано: 05 апр. 2023
Источник: nvd
CVSS3: 5.8
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this vulnerability by sending a malformed Encapsulating Security Payload (ESP) packet over an IPsec connection. A successful exploit could allow the attacker to stop ICMP traffic over an IPsec connection and cause a denial of service (DoS).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:cisco:packet_data_network_gateway:*:*:*:*:*:*:*:*
Версия до 21.28.0 (исключая)

Одно из

cpe:2.3:h:cisco:asr_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_5500:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_5700:-:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00567
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
github
почти 3 года назад

A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this vulnerability by sending a malformed Encapsulating Security Payload (ESP) packet over an IPsec connection. A successful exploit could allow the attacker to stop ICMP traffic over an IPsec connection and cause a denial of service (DoS).

CVSS3: 5.8
fstec
почти 3 года назад

Уязвимость платформы векторной обработки пакетов Vector Packet Processor (VPP) микропрограммного обеспечения шлюза сети пакетной передачи данных Cisco Packet Data Network Gateway (PGW), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.00567
Низкий

5.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
NVD-CWE-noinfo