Improper access control in Cisco Systems, Inc products - CVE-2020-3418

 

Improper access control in Cisco Systems, Inc products - CVE-2020-3418

Published: September 24, 2020 / Updated: September 29, 2020


Vulnerability identifier: #VU47141
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3418
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to an incomplete access control list (ACL) being applied prior to RUN state. A remote attacker on the local network can send ICMPv6 traffic prior to RUN state.

This vulnerability affects the following products running a vulnerable release of Cisco IOS XE Software:

  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst 9100 Access Points

Affected software

Cisco Catalyst 9800 Wireless Controller
Cisco Embedded Wireless Controller on Catalyst 9100 Access Points
Cisco IOS XE

How to mitigate CVE-2020-3418

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.2.1, Amsterdam 17.2.1r, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 17.1.1s, 17.1.1t, 17.1.2, 17.2.0.40, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.3.1, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins