Unknown
CVE-2022-20728
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)CVE-2022-20728
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- aironet 1542d firmware 017.006(001),
- aironet 1542i firmware 017.006(001),
- aironet 1562d firmware 017.006(001),
- aironet 1562e firmware 017.006(001),
- aironet 1562i firmware 017.006(001),
- aironet 1815i firmware 017.006(001),
- aironet 1815m firmware 017.006(001),
- aironet 1815t firmware 017.006(001),
- aironet 1815w firmware 017.006(001),
- aironet 1830 firmware 017.006(001),
- aironet 1840 firmware 017.006(001),
- aironet 1850e firmware 017.006(001),
- aironet 1850i firmware 017.006(001),
- aironet 2800e firmware 017.006(001),
- aironet 2800i firmware 017.006(001),
- aironet 3800e firmware 017.006(001),
- aironet 3800i firmware 017.006(001),
- aironet 3800p firmware 017.006(001),
- aironet 4800 firmware 017.006(001),
- catalyst 9105ax firmware 017.006(001),
- catalyst 9115ax firmware 017.006(001),
- catalyst 9117ax firmware 017.006(001),
- catalyst 9120ax firmware 017.006(001),
- catalyst 9124ax firmware 017.006(001),
- catalyst 9130ax firmware 017.006(001),
- catalyst iw6300 firmware 017.006(001)
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: