CVE-2022-20804: Cisco Unified Communications Products Denial of Service Vulnerability
A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect processing of certain Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by continuously sending certain Cisco Discovery Protocol packets to an affected device. A successful exploit could allow the attacker to cause a kernel panic on the system that is running the affected software, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20804?
CVE-2022-20804 is a vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME).
How severe is CVE-2022-20804?
CVE-2022-20804 has a severity score of 6.5, which is classified as medium.
What is the affected software for CVE-2022-20804?
The affected software for CVE-2022-20804 is Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) versions up to and including 14.0.
What is the impact of CVE-2022-20804?
CVE-2022-20804 could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS).
How can I fix CVE-2022-20804?
To fix CVE-2022-20804, it is recommended to apply the necessary updates or patches provided by Cisco.