CVE-2022-20682: Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to inadequate input validation of incoming CAPWAP packets encapsulating multicast DNS (mDNS) queries. An attacker could exploit this vulnerability by connecting to a wireless network and sending a crafted mDNS query, which would flow through and be processed by the wireless controller. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20682?
CVE-2022-20682 is categorized as a critical vulnerability that can lead to a denial of service condition.
How do I mitigate CVE-2022-20682?
To mitigate CVE-2022-20682, update your Cisco IOS XE software to the latest version that addresses this vulnerability.
Which Cisco products are affected by CVE-2022-20682?
CVE-2022-20682 affects the Catalyst 9000 Family running specific versions of Cisco IOS XE.
Can CVE-2022-20682 be exploited remotely?
Yes, CVE-2022-20682 can be exploited by unauthenticated remote attackers.
What impact does CVE-2022-20682 have on network operations?
The exploitation of CVE-2022-20682 can cause significant disruption to network operations through a denial of service.