CVE-2022-20728
Summary
| CVE | CVE-2022-20728 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-30 19:15:00 UTC |
| Updated | 2023-11-07 03:42:00 UTC |
| Description | A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Aironet 1542d | - | All | All | All |
| Operating System | Cisco | Aironet 1542d Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1542i | - | All | All | All |
| Operating System | Cisco | Aironet 1542i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1562d | - | All | All | All |
| Operating System | Cisco | Aironet 1562d Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1562e | - | All | All | All |
| Operating System | Cisco | Aironet 1562e Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1562i | - | All | All | All |
| Operating System | Cisco | Aironet 1562i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1815i | - | All | All | All |
| Operating System | Cisco | Aironet 1815i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1815m | - | All | All | All |
| Operating System | Cisco | Aironet 1815m Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1815t | - | All | All | All |
| Operating System | Cisco | Aironet 1815t Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1815w | - | All | All | All |
| Operating System | Cisco | Aironet 1815w Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1830 | - | All | All | All |
| Operating System | Cisco | Aironet 1830 Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1840 | - | All | All | All |
| Operating System | Cisco | Aironet 1840 Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1850e | - | All | All | All |
| Operating System | Cisco | Aironet 1850e Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 1850i | - | All | All | All |
| Operating System | Cisco | Aironet 1850i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 2800e | - | All | All | All |
| Operating System | Cisco | Aironet 2800e Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 2800i | - | All | All | All |
| Operating System | Cisco | Aironet 2800i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 3800e | - | All | All | All |
| Operating System | Cisco | Aironet 3800e Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 3800i | - | All | All | All |
| Operating System | Cisco | Aironet 3800i Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 3800p | - | All | All | All |
| Operating System | Cisco | Aironet 3800p Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Aironet 4800 | - | All | All | All |
| Operating System | Cisco | Aironet 4800 Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9105ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9105ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9115ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9115ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9117ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9117ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9120ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9120ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9124ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9124ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst 9130ax | - | All | All | All |
| Operating System | Cisco | Catalyst 9130ax Firmware | 017.006\(001\) | All | All | All |
| Hardware | Cisco | Catalyst Iw6300 | - | All | All | All |
| Operating System | Cisco | Catalyst Iw6300 Firmware | 017.006\(001\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20220927 Cisco Access Points VLAN Bypass from Native VLAN Vulnerability | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.