cisco ios CVE-2022-20761 is a vulnerability in Cisco Internetwork Operating System (IOS)
Published on April 15, 2022

Cisco 1000 Series Connected Grid Router Integrated Wireless Access Point Denial of Service Vulnerability
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to cause the integrated AP to stop processing traffic, resulting in a DoS condition. It may be necessary to manually reload the CGR1K to restore AP operation.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

Uncaught Exception

An exception is thrown from a function, but it is not caught. When an exception is not caught, it may cause the program to crash or expose sensitive information.


Products Associated with CVE-2022-20761

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-20761 are published in Cisco Internetwork Operating System (IOS):

 

Affected Versions

Cisco IOS Version n/a is affected by CVE-2022-20761

Exploit Probability

EPSS
0.10%
Percentile
27.91%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.