7.1
CVSSv2

CVE-2022-20694

Published: 15/04/2022 Updated: 07/11/2023
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.8 | Impact Score: 4 | Exploitability Score: 2.2
VMScore: 633
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote malicious user to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of a specific RPKI to Router (RTR) Protocol packet header. An attacker could exploit this vulnerability by compromising the RPKI validator server and sending a specifically crafted RTR packet to an affected device. Alternatively, the attacker could use man-in-the-middle techniques to impersonate the RPKI validator server and send a crafted RTR response packet over the established RTR TCP connection to the affected device. A successful exploit could allow the malicious user to cause a DoS condition because the BGP process could constantly restart and BGP routing could become unstable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.13.2s

cisco ios xe 3.10.6s

cisco ios xe 3.13.6s

cisco ios xe 3.14.4s

cisco ios xe 3.7.2ts

cisco ios xe 3.15.1cs

cisco ios xe 3.13.4s

cisco ios xe 16.2.1

cisco ios xe 16.1.3

cisco ios xe 3.13.0s

cisco ios xe 3.18.2s

cisco ios xe 16.1.2

cisco ios xe 3.8.0s

cisco ios xe 3.17.3s

cisco ios xe 3.16.0s

cisco ios xe 3.8.1s

cisco ios xe 3.14.1s

cisco ios xe 3.7.1s

cisco ios xe 3.12.2s

cisco ios xe 3.16.4s

cisco ios xe 3.10.5s

cisco ios xe 3.10.8s

cisco ios xe 3.9.0as

cisco ios xe 3.9.1as

cisco ios xe 3.10.1s

cisco ios xe 3.9.0s

cisco ios xe 3.17.1as

cisco ios xe 3.10.2s

cisco ios xe 3.18.2asp

cisco ios xe 3.18.3s

cisco ios xe 3.18.0as

cisco ios xe 3.7.4as

cisco ios xe 3.7.0bs

cisco ios xe 3.16.2s

cisco ios xe 3.9.2s

cisco ios xe 3.16.0cs

cisco ios xe 3.13.5s

cisco ios xe 3.7.1as

cisco ios xe 3.11.2s

cisco ios xe 3.15.0s

cisco ios xe 3.13.5as

cisco ios xe 3.14.3s

cisco ios xe 3.18.3sp

cisco ios xe 16.6.1

cisco ios xe 3.18.1sp

cisco ios xe 3.17.4s

cisco ios xe 3.17.2s

cisco ios xe 3.10.1xbs

cisco ios xe 3.7.6s

cisco ios xe 3.11.3s

cisco ios xe 3.15.3s

cisco ios xe 3.10.2ts

cisco ios xe 3.10.3s

cisco ios xe 3.16.6s

cisco ios xe 3.14.0s

cisco ios xe 3.16.5s

cisco ios xe 3.10.7s

cisco ios xe 3.7.7s

cisco ios xe 3.16.1s

cisco ios xe 3.13.7as

cisco ios xe 3.11.0s

cisco ios xe 3.12.0as

cisco ios xe 3.9.1s

cisco ios xe 3.15.1s

cisco ios xe 16.1.1

cisco ios xe 3.18.1bsp

cisco ios xe 3.7.0xas

cisco ios xe 3.7.0s

cisco ios xe 3.18.1csp

cisco ios xe 3.18.0s

cisco ios xe 3.10.0s

cisco ios xe 3.8.2s

cisco ios xe 3.17.0s

cisco ios xe 3.16.4ds

cisco ios xe 3.16.3s

cisco ios xe 3.7.4s

cisco ios xe 3.17.1s

cisco ios xe 3.18.2sp

cisco ios xe 3.15.2s

cisco ios xe 3.10.8as

cisco ios xe 16.4.1

cisco ios xe 3.14.2s

cisco ios xe 3.15.4s

cisco ios xe 3.16.2bs

cisco ios xe 3.16.1as

cisco ios xe 3.18.1s

cisco ios xe 3.12.0s

cisco ios xe 3.12.1s

cisco ios xe 3.12.4s

cisco ios xe 16.2.2

cisco ios xe 3.18.0sp

cisco ios xe 3.16.3as

cisco ios xe 3.7.5s

cisco ios xe 3.16.4as

cisco ios xe 3.13.3s

cisco ios xe 3.7.2s

cisco ios xe 3.13.6as

cisco ios xe 3.16.4bs

cisco ios xe 3.13.2as

cisco ios xe 3.11.4s

cisco ios xe 3.13.0as

cisco ios xe 3.12.3s

cisco ios xe 3.7.3s

cisco ios xe 16.3.1

cisco ios xe 3.13.1s

cisco ios xe 3.10.4s

cisco ios xe 3.16.2as

cisco ios xe 3.18.1asp

cisco ios xe 3.11.1s

cisco ios xe 3.13.8s

cisco ios xe 16.3.1a

cisco ios xe 16.3.2

cisco ios xe 16.3.3

cisco ios xe 3.16.6bs

cisco ios xe 16.5.1

cisco ios xe 3.13.7s

cisco ios xe 3.10.9s

cisco ios xe 16.5.1a

cisco ios xe 16.3.4

cisco ios xe 16.5.1b

cisco ios xe 16.4.2

cisco ios xe 3.13.9s

cisco ios xe 16.3.5b

cisco ios xe 16.3.6

cisco ios xe 16.6.3

cisco ios xe 16.8.1

cisco ios xe 16.7.1

cisco ios xe 16.6.2

cisco ios xe 16.9.1

cisco ios xe 3.16.4gs

cisco ios xe 3.16.4cs

cisco ios xe 3.16.5bs

cisco ios xe 3.16.4es

cisco ios xe 16.3.5

cisco ios xe 16.5.2

cisco ios xe 3.16.5as

cisco ios xe 3.16.0bs

cisco ios xe 16.8.1a

cisco ios xe 16.8.1s

cisco ios xe 16.8.1b

cisco ios xe 16.8.2

cisco ios xe 16.7.2

cisco ios xe 16.8.1d

cisco ios xe 16.7.3

cisco ios xe 16.7.1a

cisco ios xe 16.7.1b

cisco ios xe 16.8.1c

cisco ios xe 16.8.1e

cisco ios xe 16.4.3

cisco ios xe 3.18.3asp

cisco ios xe 3.18.1isp

cisco ios xe 16.9.1s

cisco ios xe 3.16.7as

cisco ios xe 3.18.1gsp

cisco ios xe 3.18.4s

cisco ios xe 3.16.7s

cisco ios xe 16.9.1c

cisco ios xe 3.18.3bsp

cisco ios xe 16.9.1b

cisco ios xe 3.16.7bs

cisco ios xe 3.18.4sp

cisco ios xe 16.5.3

cisco ios xe 3.18.1hsp

cisco ios xe 16.3.7

cisco ios xe 16.3.8

cisco ios xe 16.9.1d

cisco ios xe 3.13.10s

cisco ios xe 3.10.2as

cisco ios xe 3.13.6bs

cisco ios xe 16.6.4s

cisco ios xe 3.10.10s

cisco ios xe 16.6.4

cisco ios xe 3.18.5sp

cisco ios xe 3.16.8s

cisco ios xe 3.16.0as

cisco ios xe 16.10.1

cisco ios xe 16.7.4

cisco ios xe 16.9.1a

cisco ios xe 16.9.2a

cisco ios xe 16.9.2

cisco ios xe 16.6.4a

cisco ios xe 3.7.8s

cisco ios xe 3.16.10s

cisco ios xe 16.6.5

cisco ios xe 16.10.1s

cisco ios xe 16.10.1d

cisco ios xe 16.9.2s

cisco ios xe 3.16.9s

cisco ios xe 16.6.6

cisco ios xe 16.9.3h

cisco ios xe 16.6.5b

cisco ios xe 16.6.5a

cisco ios xe 16.3.9

cisco ios xe 16.9.3a

cisco ios xe 16.10.1a

cisco ios xe 16.10.1f

cisco ios xe 16.10.1g

cisco ios xe 16.10.2

cisco ios xe 16.9.3

cisco ios xe 16.10.1e

cisco ios xe 16.10.1b

cisco ios xe 16.8.3

cisco ios xe 16.9.3s

cisco ios xe 16.10.1c

cisco ios xe 3.18.6sp

cisco ios xe 16.9.4

cisco ios xe 16.6.7a

cisco ios xe 16.9.4c

cisco ios xe 3.18.7sp

cisco ios xe 16.6.7

cisco ios xe 16.10.3

cisco ios xe 16.3.10

cisco ios xe 16.9.5

cisco ios xe 16.9.5f

cisco ios xe 16.6.8

cisco ios xe 3.18.8sp

cisco ios xe 16.6.9

cisco ios xe 3.18.8asp

cisco ios xe 16.3.11

cisco ios xe 3.15.1xbs

cisco ios xe 16.9.6

cisco ios xe 3.16.10as

cisco ios xe 3.7.0xbs

cisco ios xe 3.9.0xas

cisco ios xe 3.10.1xcs

cisco ios xe 3.11.5e

cisco ios xe 3.16.10bs

cisco ios xe 3.18.9sp

cisco ios xe 16.9.7

cisco ios xe 3.18.10sp

cisco ios xe 3.16.10cs

cisco ios xe 16.6.10

cisco ios xe 16.9.8

cisco ios xe 17.6.1w

Vendor Advisories

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition This vulnerability is due to the incorrect handling of a specific RPKI ...