CVE-2022-20675 MEDIUM

CVE-2022-20675: Multiple Cisco Security Products Simple Network Management Protocol Service Denial of Service Vulnerability

Vendor Cisco
Product Cisco Web Security Appliance (WSA)
Weakness CWE-248
Published April 6, 2022
Last update November 6, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition. This vulnerability is due to an open port listener on TCP port 199. An attacker could exploit this vulnerability by connecting to TCP port 199. A successful exploit could allow the attacker to crash the SNMP service, resulting in a DoS condition.

Key dates

02Disclosure timeline

April 6, 2022 CVE published
November 6, 2024 Record updated