CVE-2022-20675 Information
Description
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA) Cisco Web Security Appliance (WSA) and Cisco Secure Email and Web Manager formerly Security Management Appliance could allow an unauthenticated remote attacker to crash the Simple Network Management Protocol (SNMP) service resulting in a denial of service (DoS) condition. This vulnerability is due to an open port listener on TCP port 199. An attacker could exploit this vulnerability by connecting to TCP port 199. A successful exploit could allow the attacker to crash the SNMP service resulting in a DoS condition.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Reference
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ESA-SNMP-JLAJksWK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
5.3
Share on: