← Back

CVE-2022-20675

nvd nist
Published: Apr 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition. This vulnerability is due to an open port listener on TCP port 199. An attacker could exploit this vulnerability by connecting to TCP port 199. A successful exploit could allow the attacker to crash the SNMP service, resulting in a DoS condition.

Affected (3)

Products: Cisco: Asyncos
1 product
Asyncos
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 14.0 to 14.02.0-020
Running on/withPlatform Versions
Cisco
Email Security Appliance
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 12.5 to 14.1.0-239
Running on/withPlatform Versions
Cisco
Secure Email And Web Manager
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 12.0 to 14.0.2-012
Running on/withPlatform Versions
Cisco
Web Security Appliance
All versions

Timeline

No history available yet.