CVE-2022-20685
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
15/11/2024
Last modified:
24/06/2025
Description
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.<br />
This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by sending crafted Modbus traffic through an affected device. A successful exploit could allow the attacker to cause the Snort process to hang, causing traffic inspection to stop.Cisco&nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:cyber_vision:3.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:cyber_vision:3.2.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



