Input validation error in Cisco Systems, Inc products - CVE-2020-3486

 

Input validation error in Cisco Systems, Inc products - CVE-2020-3486

Published: September 24, 2020 / Updated: September 29, 2020


Vulnerability identifier: #VU47144
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3486
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol. A remote attacker on the local network can send a specially crafted CAPWAP packet and perform a denial of service (DoS) attack.

This vulnerability affects the following products running a vulnerable release of Cisco IOS XE Software:

  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst 9100 Access Points

Affected software

Cisco Catalyst 9800 Wireless Controller
Cisco Embedded Wireless Controller on Catalyst 9100 Access Points
Cisco IOS XE

How to mitigate CVE-2020-3486

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.2.1, Gibraltar 16.12.2r, 16.12.1s, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 17.1.1s, 17.1.1t, 17.1.2, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.3.1, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins