CVE-2022-20697: Cisco IOS and IOS XE Software Web Services Denial of Service Vulnerability
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco IOS and IOS XE vulnerability?
The vulnerability ID is CVE-2022-20697.
What is the severity rating of the CVE-2022-20697 vulnerability?
The severity rating of CVE-2022-20697 is high.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by causing a denial of service (DoS) condition through improper resource management in the HTTP server code.
Which versions of Cisco IOS Software and Cisco IOS XE Software are affected by this vulnerability?
The affected versions include Cisco IOS 15.1(3)svr1, 15.1(3)svr2, 15.1(3)svr3, 15.1(3)svs, 15.1(3)svs1, and more. Please refer to the Cisco Security Advisory for the full list.
Is there a fix available for CVE-2022-20697 vulnerability?
Yes, Cisco has released software updates to address this vulnerability. Please refer to the Cisco Security Advisory for the available patches.