Description
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, which would cause the affected device to reload, resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Published: 2022-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-26074 A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, which would cause the affected device to reload, resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
History

Wed, 06 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco Mds 9506 Mds 9506 Firmware Mds 9513 Mds 9513 Firmware Mds 9706 Mds 9706 Firmware Mds 9710 Mds 9710 Firmware Mds 9718 Mds 9718 Firmware Nexus 1000v Nexus 1000v Firmware Nexus 3016 Nexus 3016 Firmware Nexus 3016q Nexus 3016q Firmware Nexus 3048 Nexus 3048 Firmware Nexus 3064 Nexus 3064-32t Nexus 3064-32t Firmware Nexus 3064-t Nexus 3064-t Firmware Nexus 3064-x Nexus 3064-x Firmware Nexus 3064 Firmware Nexus 3064t Nexus 3064t Firmware Nexus 3064x Nexus 3064x Firmware Nexus 3100 Nexus 3100-v Nexus 3100-v Firmware Nexus 3100-z Nexus 3100-z Firmware Nexus 3100 Firmware Nexus 3100v Nexus 3100v Firmware Nexus 31108pc-v Nexus 31108pc-v Firmware Nexus 31108pv-v Nexus 31108pv-v Firmware Nexus 31108tc-v Nexus 31108tc-v Firmware Nexus 31128pq Nexus 31128pq Firmware Nexus 3132c-z Nexus 3132c-z Firmware Nexus 3132q Nexus 3132q-v Nexus 3132q-v Firmware Nexus 3132q-x Nexus 3132q-x\/3132q-xl Nexus 3132q-x\/3132q-xl Firmware Nexus 3132q-x Firmware Nexus 3132q-xl Nexus 3132q-xl Firmware Nexus 3132q Firmware Nexus 3164q Nexus 3164q Firmware Nexus 3172 Nexus 3172 Firmware Nexus 3172pq Nexus 3172pq-xl Nexus 3172pq-xl Firmware Nexus 3172pq\/pq-xl Nexus 3172pq\/pq-xl Firmware Nexus 3172pq Firmware Nexus 3172tq Nexus 3172tq-32t Nexus 3172tq-32t Firmware Nexus 3172tq-xl Nexus 3172tq-xl Firmware Nexus 3172tq Firmware Nexus 3200 Nexus 3200 Firmware Nexus 3232c Nexus 3232c Nexus 3232c Firmware Nexus 3232c Firmware Nexus 3264c-e Nexus 3264c-e Firmware Nexus 3264q Nexus 3264q Firmware Nexus 3400 Nexus 3400 Firmware Nexus 3408-s Nexus 3408-s Firmware Nexus 34180yc Nexus 34180yc Firmware Nexus 34200yc-sm Nexus 34200yc-sm Firmware Nexus 3432d-s Nexus 3432d-s Firmware Nexus 3464c Nexus 3464c Firmware Nexus 3524 Nexus 3524-x Nexus 3524-x\/xl Nexus 3524-x\/xl Firmware Nexus 3524-x Firmware Nexus 3524-xl Nexus 3524-xl Firmware Nexus 3524 Firmware Nexus 3548 Nexus 3548-x Nexus 3548-x\/xl Nexus 3548-x\/xl Firmware Nexus 3548-x Firmware Nexus 3548-xl Nexus 3548-xl Firmware Nexus 3548 Firmware Nexus 36180yc-r Nexus 36180yc-r Firmware Nexus 3636c-r Nexus 3636c-r Firmware Nexus 5548p Nexus 5548p Firmware Nexus 5548up Nexus 5548up Firmware Nexus 5596t Nexus 5596t Firmware Nexus 5596up Nexus 5596up Firmware Nexus 5600 Nexus 5600 Firmware Nexus 56128p Nexus 56128p Firmware Nexus 5624q Nexus 5624q Firmware Nexus 5648q Nexus 5648q Firmware Nexus 5672up Nexus 5672up-16g Nexus 5672up-16g Firmware Nexus 5672up Firmware Nexus 5696q Nexus 5696q Firmware Nexus 6000 Nexus 6000 Firmware Nexus 6001 Nexus 6001 Firmware Nexus 6001p Nexus 6001p Firmware Nexus 6001t Nexus 6001t Firmware Nexus 6004 Nexus 6004 Firmware Nexus 6004x Nexus 6004x Firmware Nexus 7000 Nexus 7000 Firmware Nexus 7000 Supervisor 1 Nexus 7000 Supervisor 1 Firmware Nexus 7000 Supervisor 2 Nexus 7000 Supervisor 2 Firmware Nexus 7000 Supervisor 2e Nexus 7000 Supervisor 2e Firmware Nexus 7004 Nexus 7004 Firmware Nexus 7009 Nexus 7009 Firmware Nexus 7010 Nexus 7010 Firmware Nexus 7018 Nexus 7018 Firmware Nexus 7700 Nexus 7700 Firmware Nexus 7700 Supervisor 2e Nexus 7700 Supervisor 2e Firmware Nexus 7700 Supervisor 3e Nexus 7700 Supervisor 3e Firmware Nexus 7702 Nexus 7702 Firmware Nexus 7706 Nexus 7706 Firmware Nexus 7710 Nexus 7710 Firmware Nexus 7718 Nexus 7718 Firmware Nexus 9000 Nexus 9000 Firmware Nexus 9000v Nexus 9000v Firmware Nexus 9200 Nexus 9200 Firmware Nexus 92160yc-x Nexus 92160yc-x Firmware Nexus 9221c Nexus 9221c Firmware Nexus 92300yc Nexus 92300yc Firmware Nexus 92304qc Nexus 92304qc Firmware Nexus 92348gc-x Nexus 92348gc-x Firmware Nexus 9236c Nexus 9236c Firmware Nexus 9272q Nexus 9272q Firmware Nexus 9300 Nexus 9300 Firmware Nexus 93108tc-ex Nexus 93108tc-ex-24 Nexus 93108tc-ex-24 Firmware Nexus 93108tc-ex Firmware Nexus 93108tc-fx Nexus 93108tc-fx-24 Nexus 93108tc-fx-24 Firmware Nexus 93108tc-fx3p Nexus 93108tc-fx3p Firmware Nexus 93108tc-fx Firmware Nexus 93120tx Nexus 93120tx Firmware Nexus 93128 Nexus 93128 Firmware Nexus 93128tx Nexus 93128tx Firmware Nexus 9316d-gx Nexus 9316d-gx Firmware Nexus 93180lc-ex Nexus 93180lc-ex Firmware Nexus 93180tc-ex Nexus 93180tc-ex Firmware Nexus 93180yc-ex Nexus 93180yc-ex-24 Nexus 93180yc-ex-24 Firmware Nexus 93180yc-ex Firmware Nexus 93180yc-fx Nexus 93180yc-fx-24 Nexus 93180yc-fx-24 Firmware Nexus 93180yc-fx3 Nexus 93180yc-fx3 Firmware Nexus 93180yc-fx3s Nexus 93180yc-fx3s Firmware Nexus 93180yc-fx Firmware Nexus 93216tc-fx2 Nexus 93216tc-fx2 Firmware Nexus 93240yc-fx2 Nexus 93240yc-fx2 Firmware Nexus 9332c Nexus 9332c Firmware Nexus 9332pq Nexus 9332pq Firmware Nexus 93360yc-fx2 Nexus 93360yc-fx2 Firmware Nexus 9336c-fx2 Nexus 9336c-fx2-e Nexus 9336c-fx2-e Firmware Nexus 9336c-fx2 Firmware Nexus 9336pq Nexus 9336pq Firmware Nexus 9348gc-fxp Nexus 9348gc-fxp Firmware Nexus 93600cd-gx Nexus 93600cd-gx Firmware Nexus 9364c Nexus 9364c-gx Nexus 9364c-gx Firmware Nexus 9364c Firmware Nexus 9372px Nexus 9372px-e Nexus 9372px-e Firmware Nexus 9372px Firmware Nexus 9372tx Nexus 9372tx-e Nexus 9372tx-e Firmware Nexus 9372tx Firmware Nexus 9396px Nexus 9396px Firmware Nexus 9396tx Nexus 9396tx Firmware Nexus 9500 Supervisor A Nexus 9500 Supervisor A\+ Nexus 9500 Supervisor A\+ Firmware Nexus 9500 Supervisor A Firmware Nexus 9500 Supervisor B Nexus 9500 Supervisor B\+ Nexus 9500 Supervisor B\+ Firmware Nexus 9500 Supervisor B Firmware Nexus 9500r Nexus 9500r Firmware Nexus 9504 Nexus 9504 Firmware Nexus 9508 Nexus 9508 Firmware Nexus 9516 Nexus 9516 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-06T16:07:28.736Z

Reserved: 2021-11-02T00:00:00.000Z

Link: CVE-2022-20824

cve-icon Vulnrichment

Updated: 2024-08-03T02:24:49.938Z

cve-icon NVD

Status : Modified

Published: 2022-08-25T19:15:08.217

Modified: 2024-11-21T06:43:37.750

Link: CVE-2022-20824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses