Input validation error in Cisco IOS XE - CVE-2020-3221
Published: June 5, 2020
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of parameters in a Flexible NetFlow Version 9 record. A remote attacker can send a specially crafted Flexible NetFlow Version 9 packet to the Control and Provisioning of Wireless Access Points (CAPWAP) data port of an affected device and perform a denial of service (DoS) attack.
This vulnerability affects the following products if they are running affected release of Cisco IOS XE Software:
- Cisco Catalyst 9800 Series Wireless Controllers