CVE-2022-20915
Summary
| CVE | CVE-2022-20915 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-10 21:15:00 UTC |
| Updated | 2023-11-07 03:43:00 UTC |
| Description | A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An attacker could exploit this vulnerability by sending a crafted IPv6 packet sourced from a device on the IPv6-enabled virtual routing and forwarding (VRF) interface through the affected device. A successful exploit could allow the attacker to reload the device, resulting in a DoS condition. |
Risk And Classification
Problem Types: CWE-436
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20220928 Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerability | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 317232 Cisco Internetwork Operating System (IOS) XE Software Internet Protocol (IPv6) Virtual Private Network (VPN) over MPLS Denial of Service (DoS) Vulnerability (cisco-sa-iosxe-6vpe-dos-tJBtf5Zv)