8.6

CVE-2022-20697

A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version15.1(3)svr1
CiscoIos Version15.1(3)svr2
CiscoIos Version15.1(3)svr3
CiscoIos Version15.1(3)svs
CiscoIos Version15.1(3)svs1
CiscoIos Version15.1(3)svt1
CiscoIos Version15.1(3)svt2
CiscoIos Version15.1(3)svt3
CiscoIos Version15.1(3)svu1
CiscoIos Version15.1(3)svu2
CiscoIos Version15.1(3)svu10
CiscoIos Version15.1(3)svv1
CiscoIos Version15.2(7)e3
CiscoIos Version15.2(7)e3a
CiscoIos Version15.2(7)e3k
CiscoIos Version15.2(7)e4
CiscoIos Version15.2(8)e
CiscoIos Version15.2(234k)e
CiscoIos Version15.3(3)jk100
CiscoIos Version15.3(3)jpj8
CiscoIos Version15.9(3)m2
CiscoIos Version15.9(3)m2a
CiscoIos Version15.9(3)m3
CiscoIos Version15.9(3)m3a
CiscoIos Version15.9(3)m3b
CiscoIos Version15.9(3)m4
CiscoIos Xe Version3.11.3ae
CiscoIos Xe Version3.11.3e
CiscoIos Xe Version3.11.4e
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.45% 0.623
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
psirt@cisco.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-691 Insufficient Control Flow Management

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.