CVE-2022-20678: Cisco IOS XE Software AppNav-XE Denial of Service Vulnerability
A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco IOS XE software vulnerability?
The vulnerability ID for this Cisco IOS XE software vulnerability is CVE-2022-20678.
What is the severity of CVE-2022-20678?
The severity of CVE-2022-20678 is high.
How does CVE-2022-20678 impact Cisco IOS XE Software?
CVE-2022-20678 could allow an unauthenticated remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
Which versions of Cisco IOS XE Software are affected by CVE-2022-20678?
Cisco IOS XE Software versions 16.9.6, 16.12.4, 16.12.5, and 17.3.3 are affected by CVE-2022-20678.
How can I mitigate the CVE-2022-20678 vulnerability?
There is currently no known mitigation for CVE-2022-20678. It is recommended to apply the necessary updates or patches provided by Cisco.