CVE-2022-20685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
15/11/2024
Last modified:
24/06/2025

Description

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.<br /> This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic through an affected device. A successful exploit could allow the attacker to cause the Snort process to hang, causing traffic inspection to stop.Cisco&amp;nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:cyber_vision:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:cyber_vision:3.2.4:*:*:*:*:*:*:*