VDB

CVE-2022-20924

CVE-2022-20924 PUBLISHED CVSS 7.699999809265137 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

EPSS 0.73% · 73.0th percentile

Risk Scores

CVSS 3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.73%
73.0th percentile

Affected Products

VendorProductVersions
CiscoCisco Adaptive Security Appliance (ASA) Software9.15.1.15, 9.15.1.17, 9.15.1.16
CiscoCisco Firepower Threat Defense Software6.6.0.1, 6.6.0, 6.6.1
ciscofirepower_threat_defense6.7.0.1, 6.7.0.2, 6.7.0.3
ciscoadaptive_security_appliance_software9.15.1.1, 9.17.1.15, 9.18.1

Exploit Intelligence

Timeline

  • Nov 10, 2022 CVE Published
  • Nov 16, 2022 EPSS Score
  • Dec 29, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 24, 2023 EPSS Score
  • May 6, 2023 EPSS Score
  • Jun 18, 2023 EPSS Score
  • Jul 31, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
  • Dec 6, 2023 EPSS Score
  • Jan 18, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›