NA

CVE-2022-20728

Published: 30/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent malicious user to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the malicious user to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco aironet 1542d firmware 017.006(001)

cisco aironet 1542i firmware 017.006(001)

cisco aironet 1562i firmware 017.006(001)

cisco aironet 1562e firmware 017.006(001)

cisco aironet 1562d firmware 017.006(001)

cisco aironet 1815i firmware 017.006(001)

cisco aironet 1815m firmware 017.006(001)

cisco aironet 1815t firmware 017.006(001)

cisco aironet 1815w firmware 017.006(001)

cisco aironet 1830 firmware 017.006(001)

cisco aironet 1840 firmware 017.006(001)

cisco aironet 1850e firmware 017.006(001)

cisco aironet 1850i firmware 017.006(001)

cisco aironet 2800i firmware 017.006(001)

cisco aironet 2800e firmware 017.006(001)

cisco aironet 3800i firmware 017.006(001)

cisco aironet 3800e firmware 017.006(001)

cisco aironet 3800p firmware 017.006(001)

cisco aironet 4800 firmware 017.006(001)

cisco catalyst 9105ax firmware 017.006(001)

cisco catalyst 9115ax firmware 017.006(001)

cisco catalyst 9117ax firmware 017.006(001)

cisco catalyst 9120ax firmware 017.006(001)

cisco catalyst 9124ax firmware 017.006(001)

cisco catalyst 9130ax firmware 017.006(001)

cisco catalyst iw6300 firmware 017.006(001)

Vendor Advisories

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if the ...