VYPR
High severity7.7NVD Advisory· Published Oct 10, 2022· Updated May 27, 2026

CVE-2022-20920

CVE-2022-20920

Description

An authenticated remote attacker can cause a denial of service (DoS) on Cisco IOS and IOS XE devices by sending specially crafted SSH requests, leading to a device reload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated remote attacker can cause a denial of service (DoS) on Cisco IOS and IOS XE devices by sending specially crafted SSH requests, leading to a device reload.

Vulnerability

The vulnerability exists in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software. It is due to improper handling of resources during an exceptional situation. An authenticated, remote attacker can exploit this by continuously connecting to an affected device and sending specific SSH requests. Affected versions include various releases of Cisco IOS and IOS XE; see the Cisco Security Advisory for exact version ranges [1].

Exploitation

An attacker must have valid authentication credentials to the device. The attacker then continuously establishes SSH connections and sends specific SSH requests that trigger the resource handling flaw. No user interaction is required beyond the initial authentication. The attack can be performed remotely over the network.

Impact

Successful exploitation causes the affected device to reload, resulting in a denial of service (DoS) condition. This can disrupt network operations until the device recovers. The impact is limited to availability; no data confidentiality or integrity is compromised.

Mitigation

Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain fixes through their usual update channels. For customers without service contracts, Cisco provides instructions in the advisory [1]. No workarounds are mentioned; upgrading to a fixed version is recommended.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.