Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3409


A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to crash and reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for crafted PROFINET packets that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted PROFINET packets to an affected device for processing. A successful exploit could allow the attacker to cause the device to crash and reload, resulting in a DoS condition on the device.


Published

2020-09-24T18:15:18.353

Last Modified

2024-11-21T05:30:58.503

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 15.2\(7\)e Yes
Operating System cisco ios_xe 15.2\(7\)e Yes
Hardware cisco ie-4000-16gt4g-e - No
Hardware cisco ie-4000-16t4g-e - No
Hardware cisco ie-4000-4gc4gp4g-e - No
Hardware cisco ie-4000-4gs8gp4g-e - No
Hardware cisco ie-4000-4s8p4g-e - No
Hardware cisco ie-4000-4t4p4g-e - No
Hardware cisco ie-4000-4tc4g-e - No
Hardware cisco ie-4000-8gs4g-e - No
Hardware cisco ie-4000-8gt4g-e - No
Hardware cisco ie-4000-8gt8gp4g-e - No
Hardware cisco ie-4000-8s4g-e - No
Hardware cisco ie-4000-8t4g-e - No
Application cisco ios_xe 16.11.1a Yes
Operating System cisco ios 16.11.1a Yes
Hardware cisco ie-3200-8p2s-e - No
Hardware cisco ie-3200-8t2s-e - No
Hardware cisco ie-3300-8p2s-a - No
Hardware cisco ie-3300-8p2s-e - No
Hardware cisco ie-3300-8t2s-a - No
Hardware cisco ie-3300-8t2s-e - No
Hardware cisco ie-3300-8t2x-a - No
Hardware cisco ie-3300-8t2x-e - No
Hardware cisco ie-3400-8p2s-a - No
Hardware cisco ie-3400-8p2s-e - No
Hardware cisco ie-3400-8t2s-e - No
Hardware cisco iem-3300-14t2s - No
Hardware cisco iem-3300-16p - No
Hardware cisco iem-3300-16t - No
Hardware cisco iem-3300-6t2s - No
Hardware cisco iem-3300-8p - No
Hardware cisco iem-3300-8s - No
Hardware cisco iem-3300-8t - No
Hardware cisco iem-3400-8p - No
Hardware cisco iem-3400-8s - No
Hardware cisco iem-3400-8t - No

References