A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1100-4g Integrated Services Router
Subscribe
1100-6g Integrated Services Router
Subscribe
1101 Integrated Services Router
Subscribe
1109 Integrated Services Router
Subscribe
1111x Integrated Services Router
Subscribe
111x Integrated Services Router
Subscribe
1120 Integrated Services Router
Subscribe
1131 Integrated Services Router
Subscribe
1160 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
Asr 1001-x
Subscribe
Asr 1002-x
Subscribe
Catalyst 8000v Edge
Subscribe
Catalyst 8300-1n1s-4t2x
Subscribe
Catalyst 8300-1n1s-6t
Subscribe
Catalyst 8300-2n2s-4t2x
Subscribe
Catalyst 8300-2n2s-6t
Subscribe
Catalyst 8500
Subscribe
Catalyst 8500-4qc
Subscribe
Catalyst 8500l
Subscribe
Cloud Services Router 1000v
Subscribe
Ios Xe
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25928 | A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-06T16:25:43.535Z
Reserved: 2021-11-02T00:00:00
Link: CVE-2022-20678
Updated: 2024-08-03T02:17:53.075Z
Status : Modified
Published: 2022-04-15T15:15:12.467
Modified: 2024-11-21T06:43:18.097
Link: CVE-2022-20678
No data.
OpenCVE Enrichment
No data.
EUVD