First published: Fri Apr 15 2022(Updated: )
A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =16.9.6 | |
Cisco IOS XE | =16.12.4 | |
Cisco IOS XE | =16.12.5 | |
Cisco IOS XE | =17.3.3 | |
Cisco Catalyst 8000v Edge | ||
Cisco Cloud Services Router 1000v | ||
Cisco 1100-4g Integrated Services Router | ||
Cisco 1100-6g Integrated Services Router | ||
Cisco 1101 Integrated Services Router | ||
Cisco 1109 Integrated Services Router | ||
Cisco 1111x Integrated Services Router | ||
Cisco 111x Integrated Services Router | ||
Cisco 1120 Integrated Services Router | ||
Cisco 1131 Integrated Services Router | ||
Cisco 1160 Integrated Services Router | ||
Cisco 4221 Integrated Services Router | ||
Cisco 4331 Integrated Services Router | ||
Cisco 4431 Integrated Services Router | ||
Cisco 4461 Integrated Services Router | ||
Cisco Asr 1001-x | ||
Cisco Asr 1002-x | ||
Cisco Catalyst 8300-1n1s-4t2x | ||
Cisco Catalyst 8300-1n1s-6t | ||
Cisco Catalyst 8300-2n2s-4t2x | ||
Cisco Catalyst 8300-2n2s-6t | ||
Cisco Catalyst 8500 | ||
Cisco Catalyst 8500-4qc | ||
Cisco Catalyst 8500l |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cisco IOS XE software vulnerability is CVE-2022-20678.
The severity of CVE-2022-20678 is high.
CVE-2022-20678 could allow an unauthenticated remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
Cisco IOS XE Software versions 16.9.6, 16.12.4, 16.12.5, and 17.3.3 are affected by CVE-2022-20678.
There is currently no known mitigation for CVE-2022-20678. It is recommended to apply the necessary updates or patches provided by Cisco.