First published: Fri Apr 15 2022(Updated: )
A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =16.9.6 | |
Cisco IOS XE Web UI | =16.12.4 | |
Cisco IOS XE Web UI | =16.12.5 | |
Cisco IOS XE Web UI | =17.3.3 | |
Cisco Catalyst 8000V Edge | ||
Cisco Cloud Services Router 1000V | ||
Cisco 1100-4g/6g Integrated Services Router | ||
Cisco 1100 Integrated Services Router | ||
Cisco 1101 Integrated Services Router | ||
Cisco 1109 Integrated Services Router | ||
Cisco 111x Integrated Services Router | ||
Cisco 111x Integrated Services Router | ||
Cisco 1120 Integrated Services Router | ||
Cisco 1131 Integrated Services Router | ||
Cisco 1160 Integrated Services Router | ||
Cisco 4221 Integrated Services Router | ||
Cisco 4331/k9-rf Integrated Services Router | ||
Cisco 4431 Integrated Services Router | ||
Cisco 4441 Integrated Services Router | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002-X | ||
Cisco Catalyst 8300-1N1S-4T2X | ||
Cisco Catalyst 8300 | ||
Cisco Catalyst 8300-2N2S-4T2X | ||
Cisco Catalyst 8300 | ||
Cisco Catalyst 8500L Series Router | ||
Cisco Catalyst 8500 | ||
Cisco Catalyst 8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cisco IOS XE software vulnerability is CVE-2022-20678.
The severity of CVE-2022-20678 is high.
CVE-2022-20678 could allow an unauthenticated remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
Cisco IOS XE Software versions 16.9.6, 16.12.4, 16.12.5, and 17.3.3 are affected by CVE-2022-20678.
There is currently no known mitigation for CVE-2022-20678. It is recommended to apply the necessary updates or patches provided by Cisco.