VYPR
Unrated severityNVD Advisory· Published Apr 15, 2022· Updated Nov 6, 2024

Cisco SD-WAN vEdge Routers Denial of Service Vulnerability

CVE-2022-20717

Description

Cisco SD-WAN vEdge Routers are vulnerable to a DoS via memory exhaustion in the NETCONF process when handling large traffic, affecting software versions prior to 20.6.1 and 20.7.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco SD-WAN vEdge Routers are vulnerable to a DoS via memory exhaustion in the NETCONF process when handling large traffic, affecting software versions prior to 20.6.1 and 20.7.1.

Vulnerability

The NETCONF process in Cisco SD-WAN vEdge Routers fails to manage memory properly when the device receives large amounts of traffic. This flaw can be triggered by an authenticated local attacker, causing the device to run out of memory and crash, leading to a denial of service (DoS) condition. Affected versions include all Cisco SD-WAN vEdge Software releases earlier than 20.6.1 and 20.7.1 [1].

Exploitation

An attacker must have local access and authentication to the device. By sending specially crafted, high-volume traffic to the NETCONF process, the attacker can exhaust available memory resources. This requires the attacker to be able to generate or direct a significant amount of network traffic toward the affected device [1].

Impact

Successful exploitation results in a complete denial of service, as the device crashes and becomes unavailable. This disrupts network operations and may require manual intervention to restore service. The vulnerability does not allow code execution or privilege escalation; the impact is strictly availability [1].

Mitigation

Cisco has released fixed versions to address this vulnerability: Cisco SD-WAN vEdge Software releases 20.6.1 and 20.7.1. Customers running earlier releases should migrate to a fixed release. No workarounds are documented in the available advisory [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.