CVE-2022-20823 is a high-severity denial-of-service vulnerability affecting Cisco NX-OS Software’s OSPFv3 feature. This flaw stems from incomplete input validation of OSPFv3 packets, allowing an unauthenticated, remote attacker to crash and reload affected devices by sending a malicious OSPFv3 link-state advertisement. The vulnerability has a CVSS score of 8.6 (High), indicating a network-based attack with low complexity and high impact on availability, though OSPFv3 is disabled by default and requires an established neighbor state for exploitation. While there is no known active exploitation, public exploit code, or KEV entry, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nexus_3016_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nexus_3016q_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nexus_3048_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nexus_3064_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nexus_3064-32t_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.