CVE-2022-20870
Last modified
CVE-2022-20870 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation of IPv4 traffic. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation of IPv4 traffic. An attacker could exploit this vulnerability by sending a malformed packet out of an affected MPLS-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-20870?
How severe is CVE-2022-20870?
How do I fix CVE-2022-20870?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-20865A vulnerability in the CLI of Cisco FXOS Software could allo…6.7
- CVE-2022-20866A vulnerability in the handling of RSA keys on devices runni…7.5
- CVE-2022-20867A vulnerability in web-based management interface of the of …6.5
- CVE-2022-20868A vulnerability in the web-based management interface of Cis…8.8
- CVE-2022-20869A vulnerability in the web-based management interface of Cis…6.1
- CVE-2022-2087A vulnerability, which was classified as problematic, was fo…4.8
- CVE-2022-20871A vulnerability in the web management interface of Cisco&nbs…8.8
- CVE-2022-20872Multiple vulnerabilities in the web-based management interfa…4.8
- CVE-2022-20873Multiple vulnerabilities in the web-based management interfa…7.2
- CVE-2022-20874Multiple vulnerabilities in the web-based management interfa…7.2
- CVE-2022-20875Multiple vulnerabilities in the web-based management interfa…7.2
- CVE-2022-20876Multiple vulnerabilities in the web-based management interfa…7.2
Are you affected by CVE-2022-20870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
