CVE-2022-20933 is a denial-of-service vulnerability affecting the Cisco AnyConnect VPN server on Cisco Meraki MX and Z3 Teleworker Gateway devices. It stems from insufficient validation of client-supplied parameters during SSL VPN session establishment. An unauthenticated, remote attacker can exploit this by sending a malicious request, causing the VPN server to crash and restart, disrupting established connections and potentially preventing new ones. While the server recovers gracefully, a sustained attack could severely impact VPN availability. This vulnerability has a CVSS score of 8.6 (HIGH) due to its network attack vector, low attack complexity, and high impact on availability. There is currently no public exploit code, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.2.0, < 16.16.6CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mx64_firmware:*:*:*:*:*:*:*:* | ||
>= 17.0.0, < 17.10.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mx64_firmware:*:*:*:*:*:*:*:* | ||
>= 16.2.0, < 16.16.6CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mx64w_firmware:*:*:*:*:*:*:*:* | ||
>= 17.0.0, < 17.10.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mx64w_firmware:*:*:*:*:*:*:*:* | ||
>= 16.2.0, < 16.16.6CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mx65_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.