CVE-2022-20943 describes multiple vulnerabilities in the Snort detection engine's SMB2 processor, affecting Cisco Cyber Vision, Firepower Threat Defense, and Meraki MX Security Appliance firmware when Snort 3 is configured. An unauthenticated, remote attacker can exploit these flaws by sending a high rate of specific SMB2 packets, leading to a denial of service (DoS) condition by triggering a Snort process reload. If the "snort preserve-connection" option is enabled (default), policy bypass and malicious payload delivery are also possible. With a CVSS score of 5.8 (Medium), the attack requires no user interaction and has low complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.0:*:*:*:*:*:*:* | ||
7.0.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.0.1:*:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.1:*:*:*:*:*:*:* | ||
7.0.1.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:7.0.1.1:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:cyber_vision:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.