CVE-2022-20697
Last modified
CVE-2022-20697 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 15.1\(3\)svr1 |
| Cisco | Ios | 15.1\(3\)svr2 |
| Cisco | Ios | 15.1\(3\)svr3 |
| Cisco | Ios | 15.1\(3\)svs |
| Cisco | Ios | 15.1\(3\)svs1 |
| Cisco | Ios | 15.1\(3\)svt1 |
| Cisco | Ios | 15.1\(3\)svt2 |
| Cisco | Ios | 15.1\(3\)svt3 |
| Cisco | Ios | 15.1\(3\)svu1 |
| Cisco | Ios | 15.1\(3\)svu2 |
| Cisco | Ios | 15.1\(3\)svu10 |
| Cisco | Ios | 15.1\(3\)svv1 |
| Cisco | Ios | 15.2\(7\)e3 |
| Cisco | Ios | 15.2\(7\)e3a |
| Cisco | Ios | 15.2\(7\)e3k |
| Cisco | Ios | 15.2\(7\)e4 |
| Cisco | Ios | 15.2\(8\)e |
| Cisco | Ios | 15.2\(234k\)e |
| Cisco | Ios | 15.3\(3\)jk100 |
| Cisco | Ios | 15.3\(3\)jpj8 |
| Cisco | Ios | 15.9\(3\)m2 |
| Cisco | Ios | 15.9\(3\)m2a |
| Cisco | Ios | 15.9\(3\)m3 |
| Cisco | Ios | 15.9\(3\)m3a |
| Cisco | Ios | 15.9\(3\)m3b |
| Cisco | Ios | 15.9\(3\)m4 |
| Cisco | Ios Xe | 3.11.3ae |
| Cisco | Ios Xe | 3.11.3e |
| Cisco | Ios Xe | 3.11.4e |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-20697?
How severe is CVE-2022-20697?
How do I fix CVE-2022-20697?
Are you affected by CVE-2022-20697?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
