CVE-2022-20679: Cisco IOS XE Software IPSec Denial of Service Vulnerability
A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion that occurs while traffic on a configured IPsec tunnel is being processed. An attacker could exploit this vulnerability by sending traffic to an affected device that has a maximum transmission unit (MTU) of 1800 bytes or greater. A successful exploit could allow the attacker to cause the device to reload. To exploit this vulnerability, the attacker may need access to the trusted network where the affected device is in order to send specific packets to be processed by the device. All network devices between the attacker and the affected device must support an MTU of 1800 bytes or greater. This access requirement could limit the possibility of a successful exploit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20679?
The severity of CVE-2022-20679 is categorized as critical due to its potential to cause denial of service.
How do I fix CVE-2022-20679?
To fix CVE-2022-20679, update the Cisco IOS XE software to a version that addresses this vulnerability.
What devices are affected by CVE-2022-20679?
CVE-2022-20679 affects multiple versions of Cisco IOS XE software, including versions ranging from 3.15.1xbs to 17.6.1w.
Can CVE-2022-20679 be exploited remotely?
Yes, CVE-2022-20679 can be exploited by unauthenticated remote attackers.
What kind of impact does CVE-2022-20679 have on systems?
The impact of CVE-2022-20679 is a denial of service condition leading to device reloads.