Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3421


Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the Details section of this advisory.


Published

2020-09-24T18:15:18.917

Last Modified

2024-11-21T05:31:01.467

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-754
  • Type: Primary
    CWE-754

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xe 16.9.3 Yes
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 4321_integrated_services_router - No
Hardware cisco 4331_integrated_services_router - No
Hardware cisco 4351_integrated_services_router - No
Hardware cisco 4431_integrated_services_router - No
Hardware cisco 4461_integrated_services_router - No
Hardware cisco asr_1001-hx - No
Hardware cisco asr_1001-x - No
Hardware cisco asr_1002-hx - No
Hardware cisco asr_1002-x - No
Hardware cisco asr_1004 - No
Hardware cisco asr_1006 - No
Hardware cisco asr_1006-x - No
Hardware cisco asr_1009-x - No
Hardware cisco asr_1013 - No
Operating System cisco ios_xe 17.2 Yes
Hardware cisco 1100_integrated_services_router - No
Hardware cisco 1101_integrated_services_router - No
Hardware cisco 1109_integrated_services_router - No
Hardware cisco 1111x_integrated_services_router - No
Hardware cisco 111x_integrated_services_router - No
Hardware cisco 1120_integrated_services_router - No
Hardware cisco 1160_integrated_services_router - No
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 4331_integrated_services_router - No
Hardware cisco 4431_integrated_services_router - No
Hardware cisco 4461_integrated_services_router - No
Hardware cisco asr_1001-hx - No
Hardware cisco asr_1001-x - No
Hardware cisco asr_1002-hx - No
Hardware cisco asr_1002-x - No
Hardware cisco asr_1004 - No
Hardware cisco asr_1006 - No
Hardware cisco asr_1006-x - No
Hardware cisco asr_1009-x - No
Hardware cisco asr_1013 - No
Hardware cisco csr_1000v - No

References