← All CVEs

CVE-2022-20623

high · 8.6

A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker could exploit this vulnerability by sending a crafted stream of traffic through the device. A successful exploit could allow the attacker to cause BFD traffic to be dropped, resulting in BFD session flaps. BFD session flaps can cause route instability and dropped traffic, resulting in a denial of service (DoS) condition. This vulnerability applies to both IPv4 and IPv6 traffic.

8.6
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2022-02-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
cisconx-os>= 7.0\(3\)i6\(2\), <= 7.0\(3\)i7\(3\)
ciscon9k-c92160yc-xall versions
ciscon9k-c92300ycall versions
ciscon9k-c92304qcall versions
ciscon9k-c9232call versions
ciscon9k-c92348gc-xall versions
ciscon9k-c9236call versions
ciscon9k-c9272qall versions
ciscon9k-c93108tc-exall versions
ciscon9k-c93108tc-fxall versions
ciscon9k-c9316d-gxall versions
ciscon9k-c93180lc-exall versions
ciscon9k-c93180yc-exall versions
ciscon9k-c93180yc-fxall versions
ciscon9k-c93180yc2-fxall versions
ciscon9k-c93216tc-fx2all versions
ciscon9k-c93240yc-fx2all versions
ciscon9k-c9332call versions
ciscon9k-c93360yc-fx2all versions
ciscon9k-c9336c-fx2all versions
ciscon9k-c9348gc-fxpall versions
ciscon9k-c93600cd-gxall versions
ciscon9k-c9364call versions
ciscon9k-c9364c-gxall versions
cisconx-os>= 7.0\(3\)i6\(2\), <= 9.3\(8\)
cisconx-os>= 10.1\(1\), <= 10.2\(1\)
ciscon9k-x97160yc-exall versions
ciscon9k-x97284yc-fxall versions
ciscon9k-x9732c-exall versions
ciscon9k-x9732c-fxall versions
ciscon9k-x9736c-exall versions
ciscon9k-x9736c-fxall versions
ciscon9k-x9788tc-fxall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-20623