7.5
CVE-2022-20685
- EPSS 0.59%
- Veröffentlicht 15.11.2024 16:15:21
- Zuletzt bearbeitet 24.06.2025 14:47:25
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic through an affected device. A successful exploit could allow the attacker to cause the Snort process to hang, causing traffic inspection to stop.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Cyber Vision Version3.0.0
Cisco ≫ Cyber Vision Version3.0.1
Cisco ≫ Cyber Vision Version3.0.2
Cisco ≫ Cyber Vision Version3.0.3
Cisco ≫ Cyber Vision Version3.0.4
Cisco ≫ Cyber Vision Version3.0.5
Cisco ≫ Cyber Vision Version3.0.6
Cisco ≫ Cyber Vision Version3.1.0
Cisco ≫ Cyber Vision Version3.1.1
Cisco ≫ Cyber Vision Version3.1.2
Cisco ≫ Cyber Vision Version3.2.0
Cisco ≫ Cyber Vision Version3.2.1
Cisco ≫ Cyber Vision Version3.2.2
Cisco ≫ Cyber Vision Version3.2.3
Cisco ≫ Cyber Vision Version3.2.4
Cisco ≫ Cyber Vision Version4.0.0
Cisco ≫ Cyber Vision Version4.0.1
Cisco ≫ Firepower Threat Defense Version6.2.3
Cisco ≫ Firepower Threat Defense Version6.2.3.1
Cisco ≫ Firepower Threat Defense Version6.2.3.2
Cisco ≫ Firepower Threat Defense Version6.2.3.3
Cisco ≫ Firepower Threat Defense Version6.2.3.4
Cisco ≫ Firepower Threat Defense Version6.2.3.5
Cisco ≫ Firepower Threat Defense Version6.2.3.6
Cisco ≫ Firepower Threat Defense Version6.2.3.7
Cisco ≫ Firepower Threat Defense Version6.2.3.8
Cisco ≫ Firepower Threat Defense Version6.2.3.9
Cisco ≫ Firepower Threat Defense Version6.2.3.10
Cisco ≫ Firepower Threat Defense Version6.2.3.11
Cisco ≫ Firepower Threat Defense Version6.2.3.12
Cisco ≫ Firepower Threat Defense Version6.2.3.13
Cisco ≫ Firepower Threat Defense Version6.2.3.14
Cisco ≫ Firepower Threat Defense Version6.2.3.15
Cisco ≫ Firepower Threat Defense Version6.2.3.16
Cisco ≫ Firepower Threat Defense Version6.2.3.17
Cisco ≫ Firepower Threat Defense Version6.2.3.18
Cisco ≫ Firepower Threat Defense Version6.4.0
Cisco ≫ Firepower Threat Defense Version6.4.0.1
Cisco ≫ Firepower Threat Defense Version6.4.0.2
Cisco ≫ Firepower Threat Defense Version6.4.0.3
Cisco ≫ Firepower Threat Defense Version6.4.0.4
Cisco ≫ Firepower Threat Defense Version6.4.0.5
Cisco ≫ Firepower Threat Defense Version6.4.0.6
Cisco ≫ Firepower Threat Defense Version6.4.0.7
Cisco ≫ Firepower Threat Defense Version6.4.0.8
Cisco ≫ Firepower Threat Defense Version6.4.0.9
Cisco ≫ Firepower Threat Defense Version6.4.0.10
Cisco ≫ Firepower Threat Defense Version6.4.0.11
Cisco ≫ Firepower Threat Defense Version6.4.0.12
Cisco ≫ Firepower Threat Defense Version6.6.0
Cisco ≫ Firepower Threat Defense Version6.6.0.1
Cisco ≫ Firepower Threat Defense Version6.6.1
Cisco ≫ Firepower Threat Defense Version6.6.3
Cisco ≫ Firepower Threat Defense Version6.6.4
Cisco ≫ Firepower Threat Defense Version6.6.5
Cisco ≫ Firepower Threat Defense Version6.7.0
Cisco ≫ Firepower Threat Defense Version6.7.0.1
Cisco ≫ Firepower Threat Defense Version6.7.0.2
Cisco ≫ Firepower Threat Defense Version6.7.0.3
Cisco ≫ Firepower Threat Defense Version7.0.0
Cisco ≫ Firepower Threat Defense Version7.0.0.1
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version3.17.0s
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version3.17.1s
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.1
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.5
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.6
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.7a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.9
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.6.10
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.2
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.3
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.4
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.5
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version16.12.6
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.1.1
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.2.1r
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.3.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.3.2
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.3.3
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.3.4
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.3.4a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.4.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.4.1b
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.4.2
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.5.1
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.5.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.6.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Version17.7.1a
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versiondenali-16.3.3
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versiondenali-16.3.4
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versiondenali-16.3.5
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versiondenali-16.3.7
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versiondenali-16.3.9
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versioneverest-16.6.2
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versioneverest-16.6.3
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versioneverest-16.6.4
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.2
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.3
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.4
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.5
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.6
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.7
Cisco ≫ Unified Threat Defense Snort Intrusion Prevention System Engine Versionfuji-16.9.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.59% | 0.684 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
psirt@cisco.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-190 Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.