CVE-2022-20933 Details
Description
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters while establishing an SSL VPN session. An attacker could exploit this vulnerability by crafting a malicious request and sending it to the affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to crash and restart, resulting in the failure of the established SSL VPN connections and forcing remote users to initiate a new VPN connection and re-authenticate. A sustained attack could prevent new SSL VPN connections from being established. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention. Cisco Meraki has released software updates that address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 1, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-234 | Failure to Handle Missing Parameter | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco meraki mx64 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx64 | All versions |
CPE
Remediation
| |
| cisco meraki mx64w firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx64w | All versions |
CPE
Remediation
| |
| cisco meraki mx65 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx65 | All versions |
CPE
Remediation
| |
| cisco meraki mx65w firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx65w | All versions |
CPE
Remediation
| |
| cisco meraki mx67 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx67 | All versions |
CPE
Remediation
| |
| cisco meraki mx67cw firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx67cw | All versions |
CPE
Remediation
| |
| cisco meraki mx67w firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx67w | All versions |
CPE
Remediation
| |
| cisco meraki mx68 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx68 | All versions |
CPE
Remediation
| |
| cisco meraki mx68cw firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx68cw | All versions |
CPE
Remediation
| |
| cisco meraki mx68w firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx68w | All versions |
CPE
Remediation
| |
| cisco meraki mx75 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx75 | All versions |
CPE
Remediation
| |
| cisco meraki mx84 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx84 | All versions |
CPE
Remediation
| |
| cisco meraki mx85 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx85 | All versions |
CPE
Remediation
| |
| cisco meraki mx95 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx95 | All versions |
CPE
Remediation
| |
| cisco meraki mx100 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx100 | All versions |
CPE
Remediation
| |
| cisco meraki mx105 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx105 | All versions |
CPE
Remediation
| |
| cisco meraki mx250 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx250 | All versions |
CPE
Remediation
| |
| cisco meraki mx400 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx400 | All versions |
CPE
Remediation
| |
| cisco meraki mx450 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx450 | All versions |
CPE
Remediation
| |
| cisco meraki mx600 firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki mx600 | All versions |
CPE
Remediation
| |
| cisco meraki vmx firmware | >= 16.2.0, < 16.16.6 >= 17.0.0, < 17.10.1 |
CPE
Remediation
| |
| cisco meraki vmx | All versions |
CPE
Remediation
| |
| cisco meraki z3c firmware | All versions |
CPE
Remediation
| |
| cisco meraki z3c | All versions |
CPE
Remediation
| |
| cisco meraki z3 firmware | All versions |
CPE
Remediation
| |
| cisco meraki z3 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 31, 2022 | Initial Analysis | [email protected] |