2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-20624" ,
"sourceIdentifier" : "ykramarz@cisco.com" ,
"published" : "2022-02-23T18:15:18.577" ,
2024-11-23 15:12:23 +00:00
"lastModified" : "2024-11-21T06:43:11.060" ,
2023-11-07 21:03:21 +00:00
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming CFSoIP packets. An attacker could exploit this vulnerability by sending crafted CFSoIP packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad en la funci\u00f3n Cisco Fabric Services over IP (CFSoIP) del software Cisco NX-OS podr\u00eda permitir a un atacante remoto no autenticado provocar una condici\u00f3n de denegaci\u00f3n de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a la insuficiente validaci\u00f3n de los paquetes CFSoIP entrantes. Un atacante podr\u00eda aprovechar esta vulnerabilidad enviando paquetes CFSoIP manipulados a un dispositivo afectado. Una explotaci\u00f3n exitosa podr\u00eda permitir al atacante hacer que el dispositivo afectado se recargue, dando lugar a una condici\u00f3n de DoS"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-11-23 15:12:23 +00:00
"source" : "ykramarz@cisco.com" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
"version" : "3.1" ,
2024-11-23 15:12:23 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" ,
"baseScore" : 8.6 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
2024-11-23 15:12:23 +00:00
"scope" : "CHANGED" ,
2023-04-24 12:24:31 +02:00
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
2024-11-23 15:12:23 +00:00
"impactScore" : 4.0
2023-11-07 21:03:21 +00:00
} ,
2023-04-24 12:24:31 +02:00
{
2024-11-23 15:12:23 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"cvssData" : {
2023-11-07 21:03:21 +00:00
"version" : "3.1" ,
2024-11-23 15:12:23 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
2024-11-23 15:12:23 +00:00
"scope" : "UNCHANGED" ,
2023-04-24 12:24:31 +02:00
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
2024-11-23 15:12:23 +00:00
"impactScore" : 3.6
2023-04-24 12:24:31 +02:00
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C" ,
2024-11-23 15:12:23 +00:00
"baseScore" : 7.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 15:12:23 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
2024-11-23 15:12:23 +00:00
"source" : "ykramarz@cisco.com" ,
"type" : "Secondary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-11-23 15:12:23 +00:00
"value" : "CWE-400"
2023-04-24 12:24:31 +02:00
}
]
} ,
{
2024-11-23 15:12:23 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
2024-11-23 15:12:23 +00:00
"value" : "CWE-20"
2023-04-24 12:24:31 +02:00
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
2024-11-23 15:12:23 +00:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:nx-os:7.0\\(3\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "108374E9-8814-41C4-9474-6EE3AF24D71F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:nx-os:9.2\\(2\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D43B9D6-0991-4370-9369-C0A1EDBF6627"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:nx-os:9.2\\(3\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5FB6ADC7-97AC-4DD8-8F1B-448A63D8BE97"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:nx-os:9.3\\(3\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9FF50BFC-2DB3-4954-BC59-8B3D27D418E0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:cisco:nx-os:9.3\\(5\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2A2F42DB-B22B-4880-BA73-D0E0295190DF"
}
]
} ,
2023-04-24 12:24:31 +02:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:n9k-c9316d-gx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "122E24C3-1411-46DA-92F1-635BC0784559"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:n9k-c9332d-gx2b:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "50FE8720-EA9D-47CF-9CDB-CC09FBDD008C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:n9k-c9348d-gx2a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D100815-C171-46F4-B675-64E20D8C4FD0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:n9k-c93600cd-gx:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2D5229B-AFB2-4B28-95BB-563DBC346982"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:n9k-c9364d-gx2a:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7F0AC2DC-234F-48BA-BCC8-DE82C293C273"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3048:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FC2A6C31-438A-4CF5-A3F3-364B1672EB7D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_31108pc-v:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4E930332-CDDD-48D5-93BC-C22D693BBFA2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_31108tc-v:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7BF4B8FE-E134-4491-B5C2-C1CFEB64731B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_31128pq:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4226DA0-9371-401C-8247-E6E636A116C3"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3132c-z:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7664666F-BCE4-4799-AEEA-3A73E6AD33F4"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3132q-v:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B3293438-3D18-45A2-B093-2C3F65783336"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3132q-x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C97C29EE-9426-4BBE-8D84-AB5FF748703D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3132q-xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F43B770-D96C-44EA-BC12-9F39FC4317B9"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3164q:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FA782EB3-E8E6-4DCF-B39C-B3CBD46E4384"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3172pq:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CED628B5-97A8-4B26-AA40-BEC854982157"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3172pq-xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7BB9DD73-E31D-4921-A6D6-E14E04703588"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3172tq-xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F3229124-B097-4AAC-8ACD-2F9C89DCC3AB"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3232c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "652A2849-668D-4156-88FB-C19844A59F33"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3264c-e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "24FBE87B-8A4F-43A8-98A3-4A7D9C630937"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3264q:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6ACD09AC-8B28-4ACB-967B-AB3D450BC137"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3408-s:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7D397349-CCC6-479B-9273-FB1FFF4F34F2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_34180yc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DC7286A7-780F-4A45-940A-4AD5C9D0F201"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3432d-s:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F7AF8D7-431B-43CE-840F-CC0817D159C0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3464c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DAC204C8-1A5A-4E85-824E-DC9B8F6A802D"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3524-x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10F80A72-AD54-4699-B8AE-82715F0B58E2"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3524-xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9354B6A2-D7D6-442E-BF4C-FE8A336D9E94"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3548-x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "74CB4002-7636-4382-B33E-FBA060A13C34"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3548-xl:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10CEBF73-3EE0-459A-86C5-F8F6243FE27C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_36180yc-r:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "95D2C4C3-65CE-4612-A027-AF70CEFC3233"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_3636c-r:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "57572E4A-78D5-4D1A-938B-F05F01759612"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_92160yc-x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4283E433-7F8C-4410-B565-471415445811"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_92300yc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F80AB6FB-32FD-43D7-A9F1-80FA47696210"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_92304qc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5B2E4C1-2627-4B9D-8E92-4B483F647651"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_92348gc-x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "557ED31C-C26A-4FAE-8B14-D06B49F7F08B"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_9236c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "11411BFD-3F4D-4309-AB35-A3629A360FB0"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_9272q:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E663DE91-C86D-48DC-B771-FA72A8DF7A7C"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_9504:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "768BE390-5ED5-48A7-9E80-C4DE8BA979B1"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_9508:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDC2F709-AFBE-48EA-A3A2-DA1134534FB6"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:nexus_9516:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E02DC82-0D26-436F-BA64-73C958932B0A"
}
]
2024-11-23 15:12:23 +00:00
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
2023-04-24 12:24:31 +02:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
2024-11-23 15:12:23 +00:00
"criteria" : "cpe:2.3:o:cisco:nx-os:4.1\\(1a\\)a:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDFE7A6C-82F6-42AF-B16D-0EA236CFB3EF"
2023-11-07 21:03:21 +00:00
} ,
{
"vulnerable" : true ,
2024-11-23 15:12:23 +00:00
"criteria" : "cpe:2.3:o:cisco:nx-os:7.0\\(3\\):*:*:*:*:*:*:*" ,
"matchCriteriaId" : "108374E9-8814-41C4-9474-6EE3AF24D71F"
2023-04-24 12:24:31 +02:00
}
]
2024-11-23 15:12:23 +00:00
} ,
2023-04-24 12:24:31 +02:00
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ucs_64108:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BC04D48B-8B2F-45E1-A445-A87E92E790B8"
} ,
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:cisco:ucs_6454:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4FD096B7-6F8E-4E48-9EC4-9A10AA7D9AA0"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cfsoip-dos-tpykyDr" ,
"source" : "ykramarz@cisco.com" ,
"tags" : [
"Vendor Advisory"
]
2024-11-23 15:12:23 +00:00
} ,
{
"url" : "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cfsoip-dos-tpykyDr" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}