CVE-2022-23635Improper Authentication in Istio

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 22
Latest updateJul 31

Description

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane crashing. This endpoint is served over TLS port 15012, but does not require any authentication from the attacker. For simple installations, Istiod is typically only reachable from within the cluster, limiting the blast radi

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDistio/istio1.12.01.12.4+2
Goistio.io/istio1.13.01.13.1+2
CVEListV5istio/istio>= 1.12.0, < 1.12.4, >= 1.13.0, < 1.13.1+1

Patches

🔴Vulnerability Details

2
OSV
Unauthenticated control plane denial of service attack in Istio2022-02-23
GHSA
Unauthenticated control plane denial of service attack in Istio2022-02-23

📋Vendor Advisories

1
Red Hat
istio: unauthenticated control plane denial of service attack2022-02-22

📄Research Papers

1
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights2024-07-31
CVE-2022-23635 — Improper Authentication in Istio | cvebase