CVE-2022-20692: Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource management. An attacker could exploit this vulnerability by initiating a large number of NETCONF over SSH connections. A successful exploit could allow the attacker to exhaust resources, causing the device to reload and resulting in a DoS condition on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20692?
The severity of CVE-2022-20692 is categorized as high, as it could allow a remote attacker to cause a denial of service condition.
How do I fix CVE-2022-20692?
To fix CVE-2022-20692, you should upgrade your Cisco IOS XE Software to the recommended patched version provided by Cisco.
What devices are affected by CVE-2022-20692?
CVE-2022-20692 affects various versions of Cisco IOS XE Software, including versions 3.15.1xbs, 3.15.2xbs, and several 16.x and 17.x versions.
Can CVE-2022-20692 be exploited locally?
CVE-2022-20692 requires that an attacker be authenticated and remote, thus it cannot be exploited locally.
What type of vulnerability is CVE-2022-20692?
CVE-2022-20692 is a denial of service (DoS) vulnerability caused by insufficient resource management in the NETCONF over SSH feature.