CVE-2022-20728
published 2022-09-30CVE-2022-20728: A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from…
PriorityP423medium4.7CVSS 3.1
AVAACLPRNUINSCCNILAN
EPSS
0.25%
16.3th percentile
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | access_points_vlan | — | — |
| cisco | aironet_1542d_firmware | — | — |
| cisco | aironet_1542i_firmware | — | — |
| cisco | aironet_1562d_firmware | — | — |
| cisco | aironet_1562e_firmware | — | — |
| cisco | aironet_1562i_firmware | — | — |
| cisco | aironet_1815i_firmware | — | — |
| cisco | aironet_1815m_firmware | — | — |
| cisco | aironet_1815t_firmware | — | — |
| cisco | aironet_1815w_firmware | — | — |
| cisco | aironet_1830_firmware | — | — |
| cisco | aironet_1840_firmware | — | — |
| cisco | aironet_1850e_firmware | — | — |
| cisco | aironet_1850i_firmware | — | — |
| cisco | aironet_2800e_firmware | — | — |
| cisco | aironet_2800i_firmware | — | — |
| cisco | aironet_3800e_firmware | — | — |
| cisco | aironet_3800i_firmware | — | — |
| cisco | aironet_3800p_firmware | — | — |
| cisco | aironet_4800_firmware | — | — |
| cisco | catalyst_9105ax_firmware | — | — |
| cisco | catalyst_9115ax_firmware | — | — |
| cisco | catalyst_9117ax_firmware | — | — |
| cisco | catalyst_9120ax_firmware | — | — |
| cisco | catalyst_9124ax_firmware | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
vendor_cisco·2022-09-27·CVSS 4.7
CVE-2022-20728 [MEDIUM] CWE-284 Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device.
This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Cisco has released software update
Cisco
Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20728 Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
CVE-2022-20728: Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed. Cisco has released s
GHSA
GHSA-66v9-vq83-62h5: A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packet
ghsa_unreviewed·2022-10-01
CVE-2022-20728 [MEDIUM] GHSA-66v9-vq83-62h5: A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packet
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-30
Published