Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2022-20697

Disclosure Date: April 13, 2022
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.6 High
Impact Score:
4
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Changed
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • cisco

Products

  • ios 15.1(3)svr1,
  • ios 15.1(3)svr2,
  • ios 15.1(3)svr3,
  • ios 15.1(3)svs,
  • ios 15.1(3)svs1,
  • ios 15.1(3)svt1,
  • ios 15.1(3)svt2,
  • ios 15.1(3)svt3,
  • ios 15.1(3)svu1,
  • ios 15.1(3)svu10,
  • ios 15.1(3)svu2,
  • ios 15.1(3)svv1,
  • ios 15.2(234k)e,
  • ios 15.2(7)e3,
  • ios 15.2(7)e3a,
  • ios 15.2(7)e3k,
  • ios 15.2(7)e4,
  • ios 15.2(8)e,
  • ios 15.3(3)jk100,
  • ios 15.3(3)jpj8,
  • ios 15.9(3)m2,
  • ios 15.9(3)m2a,
  • ios 15.9(3)m3,
  • ios 15.9(3)m3a,
  • ios 15.9(3)m3b,
  • ios 15.9(3)m4,
  • ios xe 3.11.3ae,
  • ios xe 3.11.3e,
  • ios xe 3.11.4e

Additional Info

Technical Analysis