Input validation error in Cisco cBR-8 Converged Broadband and Cisco IOS XE - CVE-2020-3526

 

Input validation error in Cisco cBR-8 Converged Broadband and Cisco IOS XE - CVE-2020-3526

Published: September 24, 2020 / Updated: September 30, 2020


Vulnerability identifier: #VU47210
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3526
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Common Open Policy Service (COPS) engine. A remote attacker can send a specially crafted COPS message and perform a denial of service (DoS) attack.


Affected software

Cisco cBR-8 Converged Broadband
Cisco IOS XE

How to mitigate CVE-2020-3526

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, Gibraltar 16.12.4, 16.12.1y, 16.12.1z, 16.12.3s, 16.12.3.22, 16.12.4, 16.12.4a, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.2.2, 17.3.0.19, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins