Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20051


A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this vulnerability by sending a malformed Encapsulating Security Payload (ESP) packet over an IPsec connection. A successful exploit could allow the attacker to stop ICMP traffic over an IPsec connection and cause a denial of service (DoS).


Published

2023-04-05T17:15:07.530

Last Modified

2024-11-21T07:40:26.517

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco packet_data_network_gateway < 21.28.0 Yes
Hardware cisco asr_5000 - No
Hardware cisco asr_5500 - No
Hardware cisco asr_5700 - No

References