CVE-2022-20728
4.7
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Affected (26)
Products: Cisco: Aironet 1542d Firmware, Aironet 1542i Firmware, Aironet 1562i Firmware, Aironet 1562e Firmware, Aironet 1562d Firmware, Aironet 1815i Firmware, Aironet 1815m Firmware, Aironet 1815t Firmware, Aironet 1815w Firmware, Aironet 1830 Firmware, Aironet 1840 Firmware, Aironet 1850e Firmware, Aironet 1850i Firmware, Aironet 2800i Firmware, Aironet 2800e Firmware, Aironet 3800i Firmware, Aironet 3800e Firmware, Aironet 3800p Firmware, Aironet 4800 Firmware, Catalyst 9105ax Firmware, Catalyst 9115ax Firmware, Catalyst 9117ax Firmware, Catalyst 9120ax Firmware, Catalyst 9124ax Firmware, Catalyst 9130ax Firmware, Catalyst Iw6300 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1542d | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1542i | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1562i | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1562e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1562d | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1815i | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1815m | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1815t | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1815w | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1830 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1840 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1850e | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 1850i | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 2800i | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 2800e | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 3800i | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 3800e | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 3800p | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Aironet 4800 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9105ax | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9115ax | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9117ax | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9120ax | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9124ax | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9130ax | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version 017.006(001) |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst Iw6300 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.