CVE-2022-20824
Last modified
CVE-2022-20824 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, which would cause the affected device to reload, resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Mds 9506 Firmware | All versions |
| Cisco | Mds 9513 Firmware | All versions |
| Cisco | Mds 9706 Firmware | All versions |
| Cisco | Mds 9710 Firmware | All versions |
| Cisco | Mds 9718 Firmware | All versions |
| Cisco | Nexus 1000v Firmware | All versions |
| Cisco | Nexus 3016 Firmware | All versions |
| Cisco | Nexus 3016q Firmware | All versions |
| Cisco | Nexus 3048 Firmware | All versions |
| Cisco | Nexus 3064 Firmware | All versions |
| Cisco | Nexus 3064-32t Firmware | All versions |
| Cisco | Nexus 3064-T Firmware | All versions |
| Cisco | Nexus 3064-X Firmware | All versions |
| Cisco | Nexus 3064t Firmware | All versions |
| Cisco | Nexus 3064x Firmware | All versions |
| Cisco | Nexus 3100 Firmware | All versions |
| Cisco | Nexus 3100-V Firmware | All versions |
| Cisco | Nexus 3100-Z Firmware | All versions |
| Cisco | Nexus 3100v Firmware | All versions |
| Cisco | Nexus 31108pc-V Firmware | All versions |
| Cisco | Nexus 31108pv-V Firmware | All versions |
| Cisco | Nexus 31108tc-V Firmware | All versions |
| Cisco | Nexus 31128pq Firmware | All versions |
| Cisco | Nexus 3132c-Z Firmware | All versions |
| Cisco | Nexus 3132q Firmware | All versions |
| Cisco | Nexus 3132q-V Firmware | All versions |
| Cisco | Nexus 3132q-X Firmware | All versions |
| Cisco | Nexus 3132q-X\/3132q-Xl Firmware | All versions |
| Cisco | Nexus 3132q-Xl Firmware | All versions |
| Cisco | Nexus 3164q Firmware | All versions |
| Cisco | Nexus 3172 Firmware | All versions |
| Cisco | Nexus 3172pq Firmware | All versions |
| Cisco | Nexus 3172pq-Xl Firmware | All versions |
| Cisco | Nexus 3172pq\/Pq-Xl Firmware | All versions |
| Cisco | Nexus 3172tq Firmware | All versions |
| Cisco | Nexus 3172tq-32t Firmware | All versions |
| Cisco | Nexus 3172tq-Xl Firmware | All versions |
| Cisco | Nexus 3200 Firmware | All versions |
| Cisco | Nexus 3232c Firmware | All versions |
| Cisco | Nexus 3232c Firmware | All versions |
| Cisco | Nexus 3264c-E Firmware | All versions |
| Cisco | Nexus 3264q Firmware | All versions |
| Cisco | Nexus 3400 Firmware | All versions |
| Cisco | Nexus 3408-S Firmware | All versions |
| Cisco | Nexus 34180yc Firmware | All versions |
| Cisco | Nexus 34200yc-Sm Firmware | All versions |
| Cisco | Nexus 3432d-S Firmware | All versions |
| Cisco | Nexus 3464c Firmware | All versions |
| Cisco | Nexus 3524 Firmware | All versions |
| Cisco | Nexus 3524-X Firmware | All versions |
Showing 50 of 144 affected configurations. See NVD for the full list.
References
- https://security.netapp.com/advisory/ntap-20220923-0001/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220923-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-20824?
How severe is CVE-2022-20824?
How do I fix CVE-2022-20824?
Are you affected by CVE-2022-20824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
