Vulnerability Name:

CVE-2022-2929 (CCN-237823)

Assigned:2022-10-05
Published:2022-10-05
Updated:2023-05-03
Summary:
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.1 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2022-2929

Source: XF
Type: UNKNOWN
isc-dhcp-cve20222929-dos(237823)

Source: CCN
Type: ISC Web site
CVE-2022-2929 DHCP memory leak

Source: security-officer@isc.org
Type: Vendor Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: Mailing List, Third Party Advisory
security-officer@isc.org

Source: security-officer@isc.org
Type: UNKNOWN
security-officer@isc.org

Source: CCN
Type: IBM Security Bulletin 6844199 (i)
ISC DHCP server for IBM i is vulnerable to a denial of service attack due to a memory leak and refererence count overflow (CVE-2022-2928, CVE-2022-2929)

Source: CCN
Type: Mend Vulnerability Database
CVE-2022-2929

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:isc:dhcp:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.3:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.2:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.3:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.2:b1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.3:p2:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:a2:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.1:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.4:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:b1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.1:b1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:b2:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.4:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:a1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.1:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.0:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.3:p1:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.5:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.2.8:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.3.0:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.3.3:-:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:isc:dhcp:4.4.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:ibm:i:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.4:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7481
    P
    dhcp-4.3.6.P1-150000.6.17.1 on GA media (Moderate)
    2023-06-12
    BACK
    isc dhcp 3.0
    isc dhcp 4.0.0
    isc dhcp 4.2.3
    isc dhcp 4.2.2
    isc dhcp 4.2.3 p1
    isc dhcp 4.2.2 rc1
    isc dhcp 4.2.2 b1
    isc dhcp 4.2.0
    isc dhcp 4.2.3 p2
    isc dhcp 4.2.0 a2
    isc dhcp 4.2.1 rc1
    isc dhcp 4.2.4
    isc dhcp 4.2.0 b1
    isc dhcp 4.2.1 b1
    isc dhcp 4.2.0 b2
    isc dhcp 4.2.0 rc1
    isc dhcp 4.2.4 p1
    isc dhcp 4.2.0 a1
    isc dhcp 4.2.1
    isc dhcp 4.2.0 p1
    isc dhcp 4.2.3 p1
    isc dhcp 4.2.5
    isc dhcp 4.2.8
    isc dhcp 4.3.0
    isc dhcp 4.3.3
    isc dhcp 4.3.5
    isc dhcp 4.4.1
    isc dhcp 4.4.2
    ibm i 7.2
    ibm i 7.3
    ibm i 7.4
    ibm i 7.5