CVEPublished 2022-10-10Modified 2026-05-270 articles on news6 live referencesNVD data

CVE-2022-20920Cisco · Ios

Vulnerability data via NVD (ingested)

CVSS v3.1
7.7
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS percentile
77
Exploit Prediction Scoring System · top 23% of all CVEs
Description

A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affected device and sending specific SSH requests. A successful exploit could allow the attacker to cause the affected device to reload.

Timeline
Published 2022-10-10
Modified 2026-05-27

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2022-20920 on GitHub.
We haven't classified any articles referencing CVE-2022-20920 yet. The external references above still apply.