Input validation error in Cisco Systems, Inc products - CVE-2020-3390

 

Input validation error in Cisco Systems, Inc products - CVE-2020-3390

Published: September 24, 2020 / Updated: September 29, 2020


Vulnerability identifier: #VU47153
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3390
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in Simple Network Management Protocol (SNMP) trap generation for wireless clients. A remote attacker on the local network can send an 802.1x packet with crafted parameters during the wireless authentication setup phase of a connection and perform a denial of service (DoS) attack.

This vulnerability affects the following products running a vulnerable release of Cisco IOS XE Software:

  • Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
  • Catalyst 9800 Series Wireless Controllers
  • Embedded Wireless Controller on Catalyst 9100 Access Points

Affected software

Cisco Catalyst 9800 Wireless Controller
Cisco Embedded Wireless Controller on Catalyst 9100 Access Points
Cisco IOS XE

How to mitigate CVE-2020-3390

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 17.1.1s, 17.1.1t, 17.1.2, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins