Vulnslist

find the latest Cisco vulnerabilities

Cisco Smart Software Manager On-Prem Denial of Service Vulnerability

cisco-sa-onprem-privesc-tP6uNZOS · High · Published · Updated

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous device registrations on Cisco SSM On-Prem. An attacker could exploit this vulnerability by sending multiple device registration requests to Cisco SSM On-Prem. A successful exploit could allow the attacker to cause a DoS condition on an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-privesc-tP6uNZOS

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2022-20808
Cisco Bug IDsCSCvy25011
CVSS ScoreBase 7.7
Base 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Smart Software Manager On-Prem

Related Products

Product CVE Evidence
Cisco Smart Software Manager On-Prem CVE-2022-20808 Cisco OpenVuln