CVE-2022-20943
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2022
Last modified:
25/01/2024
Description
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device.<br />
<br />
These vulnerabilities are due to improper management of system resources when the Snort detection engine is processing SMB2 traffic. An attacker could exploit these vulnerabilities by sending a high rate of certain types of SMB2 packets through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process, resulting in a DoS condition.<br />
<br />
Note: When the snort preserve-connection option is enabled for the Snort detection engine, a successful exploit could also allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network. The snort preserve-connection setting is enabled by default. See the Details ["#details"] section of this advisory for more information.<br />
<br />
Note: Only products that have Snort 3 configured are affected. Products that are configured with Snort 2 are not affected.
Impact
Base Score 3.x
5.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:firepower_threat_defense:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_threat_defense:7.0.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_threat_defense:7.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:firepower_threat_defense:7.0.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



