CVE-2022-20717

MEDIUM

Cisco SD-WAN vEdge Routers - DoS

Title source: llm
STIX 2.1

Description

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run out of memory, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient memory management when an affected device receives large amounts of traffic. An attacker could exploit this vulnerability by sending malicious traffic to an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770 CWE-789
Status published
Products (2)
cisco/sd-wan_vedge_router 20.7
cisco/sd-wan_vedge_router < 20.6
Published Apr 15, 2022
Tracked Since Feb 18, 2026