HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2022-20919

CVSS 8.6v3.1pub. 2022-09-30upd. 2024-11-21

A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation during processing of CIP packets. An attacker could exploit this vulnerability by sending a malformed CIP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a DoS condition.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco 1000 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 2p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1120 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1131 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1160 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4221 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4431 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4451 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4451 X Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4461 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco Asr 1000 Esp100

    HW
    Cisco
    all versions
  • Cisco Asr 1000 X

    HW
    Cisco
    all versions
  • Cisco Asr 1001

    HW
    Cisco
    all versions
  • Cisco Asr 1001 Hx

    HW
    Cisco
    all versions
  • Cisco Asr 1001 Hx R

    HW
    Cisco
    all versions
  • Cisco Asr 1001 X

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓same product

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓same product

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)