← Back

CVE-2022-20697

nvd nist
Published: Apr 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Affected (29)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 15.1(3)svr1
Version 15.1(3)svr2
Version 15.1(3)svr3
Version 15.1(3)svs1
Version 15.1(3)svs
Version 15.1(3)svt1
Version 15.1(3)svt2
Version 15.1(3)svt3
Version 15.1(3)svu10
Version 15.1(3)svu1
Version 15.1(3)svu2
Version 15.1(3)svv1
Version 15.2(234k)e
Version 15.2(7)e3
Version 15.2(7)e3a
Version 15.2(7)e3k
Version 15.2(7)e4
Version 15.2(8)e
Version 15.3(3)jk100
Version 15.3(3)jpj8
Version 15.9(3)m2
Version 15.9(3)m2a
Version 15.9(3)m3
Version 15.9(3)m3a
Version 15.9(3)m3b
Version 15.9(3)m4
Cisco
Version 3.11.3ae
Version 3.11.3e
Version 3.11.4e

Timeline

No history available yet.