Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-20717


A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.


Published

2022-04-15T15:15:13.113

Last Modified

2024-11-21T06:43:24.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-789
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco sd-wan_vedge_router ≤ 20.6 Yes
Application cisco sd-wan_vedge_router 20.7 Yes
Hardware cisco 1100_integrated_services_router - No
Hardware citrix sd-wan_1000 - No
Hardware citrix sd-wan_110 - No
Hardware citrix sd-wan_1100 - No
Hardware citrix sd-wan_2000 - No
Hardware citrix sd-wan_210 - No
Hardware citrix sd-wan_2100 - No
Hardware citrix sd-wan_5100 - No

References