CVE-2022-20824

HIGH

Cisco FXOS and NX-OS - Unauthenticated Stack-based Buffer Overflow via Cisco Discovery Protocol

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are within a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, which would cause the affected device to reload, resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220923-0001/

Scores

CVSS v3 8.8
EPSS 0.0014
EPSS Percentile 33.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (50)
cisco/mds_9506_firmware
cisco/mds_9513_firmware
cisco/mds_9706_firmware
cisco/mds_9710_firmware
cisco/mds_9718_firmware
cisco/nexus_1000v_firmware
cisco/nexus_3016_firmware
cisco/nexus_3016q_firmware
cisco/nexus_3048_firmware
cisco/nexus_3064-32t_firmware
... and 40 more
Published Aug 25, 2022
Tracked Since Feb 18, 2026