Description
A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisco Discovery Protocol service. An attacker could exploit this vulnerability by sending a series of malicious Cisco Discovery Protocol messages to an affected device. A successful exploit could allow the attacker to cause the Cisco Discovery Protocol service to fail and restart. In rare conditions, repeated failures of the process could occur, which could cause the entire device to restart.
Published: 2022-02-23
Score: 4.3 Medium
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-25875 A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisco Discovery Protocol service. An attacker could exploit this vulnerability by sending a series of malicious Cisco Discovery Protocol messages to an affected device. A successful exploit could allow the attacker to cause the Cisco Discovery Protocol service to fail and restart. In rare conditions, repeated failures of the process could occur, which could cause the entire device to restart.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0237}

epss

{'score': 0.02487}


Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Firepower 4110 Firepower 4112 Firepower 4115 Firepower 4120 Firepower 4125 Firepower 4140 Firepower 4145 Firepower 4150 Firepower 9300 Firepower Extensible Operating System Mds 9132t Mds 9148s Mds 9148t Mds 9222i Mds 9250i Mds 9396s Mds 9396t Mds 9506 Mds 9513 Mds 9706 Mds 9710 Mds 9718 N77-f312ck-26 N77-f324fq-25 N77-f348xp-23 N77-f430cq-36 N77-m312cq-26l N77-m324fq-25l N77-m348xp-23l N7k-f248xp-25e N7k-f306ck-25 N7k-f312fq-25 N7k-m202cf-22l N7k-m206fq-23l N7k-m224xp-23l N7k-m324fq-25l N7k-m348xp-25l N9k-c9316d-gx N9k-c9332d-gx2b N9k-c9348d-gx2a N9k-c93600cd-gx N9k-c9364d-gx2a Nexus 1000v Nexus 1000ve Nexus 3048 Nexus 31108pc-v Nexus 31108tc-v Nexus 31128pq Nexus 3132c-z Nexus 3132q-v Nexus 3132q-x Nexus 3132q-xl Nexus 3164q Nexus 3172pq Nexus 3172pq-xl Nexus 3172tq-xl Nexus 3232c Nexus 3264c-e Nexus 3264q Nexus 3408-s Nexus 34180yc Nexus 3432d-s Nexus 3464c Nexus 3524-x Nexus 3524-xl Nexus 3548-x Nexus 3548-xl Nexus 36180yc-r Nexus 3636c-r Nexus 7000 10-slot Nexus 7000 18-slot Nexus 7000 4-slot Nexus 7000 9-slot Nexus 7000 Supervisor 1 Nexus 7000 Supervisor 2 Nexus 7000 Supervisor 2e Nexus 7700 10-slot Nexus 7700 18-slot Nexus 7700 2-slot Nexus 7700 6-slot Nexus 7700 Supervisor 2e Nexus 7700 Supervisor 3e Nexus 92160yc-x Nexus 92300yc Nexus 92304qc Nexus 92348gc-x Nexus 9236c Nexus 9272q Nexus 93108tc-ex Nexus 93108tc-fx Nexus 93108tc-fx3p Nexus 93120tx Nexus 93216tc-fx2 Nexus 9332c Nexus 9336c-fx2 Nexus 9336c-fx2-e Nexus 9348gc-fxp Nexus 9364c Nexus 9364c-gx Nexus 9504 Nexus 9508 Nexus 9516 Nx-os Ucs 6248up Ucs 6296up Ucs 6324 Ucs 6332 Ucs 6332-16up Ucs 64108 Ucs 6454
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-06T16:29:50.135Z

Reserved: 2021-11-02T00:00:00.000Z

Link: CVE-2022-20625

cve-icon Vulnrichment

Updated: 2024-08-03T02:17:52.933Z

cve-icon NVD

Status : Modified

Published: 2022-02-23T18:15:18.637

Modified: 2024-11-21T06:43:11.237

Link: CVE-2022-20625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses