CVE-2022-20922 describes multiple vulnerabilities in the Snort detection engine's SMB2 processor, affecting Cisco Cyber Vision, Firepower Threat Defense, and Umbrella Insights Virtual Appliance when configured with Snort 3. These flaws stem from improper resource management during SMB2 traffic processing. An unauthenticated, remote attacker can exploit this by sending a high rate of specific SMB2 packets, leading to a denial of service (DoS) condition by triggering a Snort process reload. If the "snort preserve-connection" option is enabled (which is default), policy bypass and malicious payload delivery are also possible. The vulnerability has a CVSS score of 6.5 (Medium), indicating network attack vector, low attack complexity, and potential for limited integrity and availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0:*:*:*:*:*:*:* | ||
7.1.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0.1:*:*:*:*:*:*:* | ||
7.1.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.1.0.2:*:*:*:*:*:*:* | ||
7.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.2.0:*:*:*:*:*:*:* | ||
7.2.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.