4.7

CVE-2022-20728

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoAironet 1542d Firmware Version017.006(001)
   CiscoAironet 1542d Version-
CiscoAironet 1542i Firmware Version017.006(001)
   CiscoAironet 1542i Version-
CiscoAironet 1562i Firmware Version017.006(001)
   CiscoAironet 1562i Version-
CiscoAironet 1562e Firmware Version017.006(001)
   CiscoAironet 1562e Version-
CiscoAironet 1562d Firmware Version017.006(001)
   CiscoAironet 1562d Version-
CiscoAironet 1815i Firmware Version017.006(001)
   CiscoAironet 1815i Version-
CiscoAironet 1815m Firmware Version017.006(001)
   CiscoAironet 1815m Version-
CiscoAironet 1815t Firmware Version017.006(001)
   CiscoAironet 1815t Version-
CiscoAironet 1815w Firmware Version017.006(001)
   CiscoAironet 1815w Version-
CiscoAironet 1830 Firmware Version017.006(001)
   CiscoAironet 1830 Version-
CiscoAironet 1840 Firmware Version017.006(001)
   CiscoAironet 1840 Version-
CiscoAironet 1850e Firmware Version017.006(001)
   CiscoAironet 1850e Version-
CiscoAironet 1850i Firmware Version017.006(001)
   CiscoAironet 1850i Version-
CiscoAironet 2800i Firmware Version017.006(001)
   CiscoAironet 2800i Version-
CiscoAironet 2800e Firmware Version017.006(001)
   CiscoAironet 2800e Version-
CiscoAironet 3800i Firmware Version017.006(001)
   CiscoAironet 3800i Version-
CiscoAironet 3800e Firmware Version017.006(001)
   CiscoAironet 3800e Version-
CiscoAironet 3800p Firmware Version017.006(001)
   CiscoAironet 3800p Version-
CiscoAironet 4800 Firmware Version017.006(001)
   CiscoAironet 4800 Version-
CiscoCatalyst 9105ax Firmware Version017.006(001)
   CiscoCatalyst 9105ax Version-
CiscoCatalyst 9115ax Firmware Version017.006(001)
   CiscoCatalyst 9115ax Version-
CiscoCatalyst 9117ax Firmware Version017.006(001)
   CiscoCatalyst 9117ax Version-
CiscoCatalyst 9120ax Firmware Version017.006(001)
   CiscoCatalyst 9120ax Version-
CiscoCatalyst 9124ax Firmware Version017.006(001)
   CiscoCatalyst 9124ax Version-
CiscoCatalyst 9130ax Firmware Version017.006(001)
   CiscoCatalyst 9130ax Version-
CiscoCatalyst Iw6300 Firmware Version017.006(001)
   CiscoCatalyst Iw6300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.329
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
psirt@cisco.com 4.7 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.