CVE-2022-20920

Published Oct 10, 2022

Last updated 12 days ago

Overview

Description
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affected device and sending specific SSH requests. A successful exploit could allow the attacker to cause the affected device to reload.
Source
psirt@cisco.com
NVD status
Modified
Products
ios, ios_xe

Risk scores

CVSS 3.1

Type
Primary
Base score
7.7
Impact score
4
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity
HIGH

Weaknesses

psirt@cisco.com
CWE-755
nvd@nist.gov
CWE-755
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-755

Social media

Hype score
Not currently trending

Configurations