CVE-2022-20697

A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
ciscoCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
ciscoios
15.1\(3\)svr1
ciscoios
15.1\(3\)svr2
ciscoios
15.1\(3\)svr3
ciscoios
15.1\(3\)svs
ciscoios
15.1\(3\)svs1
ciscoios
15.1\(3\)svt1
ciscoios
15.1\(3\)svt2
ciscoios
15.1\(3\)svt3
ciscoios
15.1\(3\)svu1
ciscoios
15.1\(3\)svu2
ciscoios
15.1\(3\)svu10
ciscoios
15.1\(3\)svv1
ciscoios
15.2\(7\)e3
ciscoios
15.2\(7\)e3a
ciscoios
15.2\(7\)e3k
ciscoios
15.2\(7\)e4
ciscoios
15.2\(8\)e
ciscoios
15.2\(234k\)e
ciscoios
15.3\(3\)jk100
ciscoios
15.3\(3\)jpj8
ciscoios
15.9\(3\)m2
ciscoios
15.9\(3\)m2a
ciscoios
15.9\(3\)m3
ciscoios
15.9\(3\)m3a
ciscoios
15.9\(3\)m3b
ciscoios
15.9\(3\)m4
ciscoios_xe
3.11.3ae:ae
ciscoios_xe
3.11.3e:e
ciscoios_xe
3.11.4e:e
𝑥
= Vulnerable software versions