VDB
CVE-2022-20924
CVE-2022-20924
PUBLISHED
CVSS 7.699999809265137 HIGH
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
EPSS 0.73% · 73.0th percentile
Risk Scores
CVSS 3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.73%
73.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | 9.15.1.15, 9.15.1.17, 9.15.1.16 |
| Cisco | Cisco Firepower Threat Defense Software | 6.6.0.1, 6.6.0, 6.6.1 |
| cisco | firepower_threat_defense | 6.7.0.1, 6.7.0.2, 6.7.0.3 |
| cisco | adaptive_security_appliance_software | 9.15.1.1, 9.17.1.15, 9.18.1 |
Exploit Intelligence
Timeline
- Nov 10, 2022 CVE Published
- Nov 16, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 24, 2023 EPSS Score
- May 6, 2023 EPSS Score
- Jun 18, 2023 EPSS Score
- Jul 31, 2023 EPSS Score
- Oct 24, 2023 EPSS Score
- Dec 6, 2023 EPSS Score
- Jan 18, 2024 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-snmp-dos-qsqBNM6x advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fw3100-secure-boot-5M8mUh26 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssl-client-dos-cCrQPkA advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcsfr-snmp-access-6gqgtJ4S advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-dap-dos-GhYZBxDU advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-dos-OwEunWJN advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM advisory
- cisco-sa-asaftd-snmp-dos-qsqBNM6x url
- https://nvd.nist.gov/vuln/detail/CVE-2022-20924 advisory