Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3465


A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this vulnerability by sending the Ethernet frames onto the Ethernet segment. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.


Published

2020-09-24T18:15:19.557

Last Modified

2024-11-21T05:31:07.557

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xe 16.6.9 Yes
Operating System cisco ios_xe 17.4.1 Yes
Hardware cisco 1100-4p - No
Hardware cisco 1100-8p - No
Hardware cisco 1100_terminal_services_gateways - No
Hardware cisco 1101-4p - No
Hardware cisco 1109-2p - No
Hardware cisco 1109-4p - No
Hardware cisco 1111x-8p - No
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 4331_integrated_services_router - No
Hardware cisco 4431_integrated_services_router - No
Hardware cisco 4461_integrated_services_router - No
Hardware cisco 9800-cl - No
Hardware cisco 9800-l - No
Hardware cisco csr_1000v - No
Hardware cisco esr6300 - No
Hardware cisco ir_1101 - No
Hardware cisco isrv - No
Hardware cisco vg400 - No

References