Vulnerability identifier: #VU47210
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3526
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Common Open Policy Service (COPS) engine. A remote attacker can send a specially crafted COPS message and perform a denial of service (DoS) attack.
Affected software
Cisco cBR-8 Converged Broadband
Cisco IOS XE
How to mitigate CVE-2020-3526
Install updates from vendor's website.
Cisco IOS XE - addressed in versions Amsterdam 17.2.1, Amsterdam 17.2.1r, Amsterdam 17.3.1, Gibraltar 16.12.4, 16.12.1y, 16.12.1z, 16.12.3s, 16.12.3.22, 16.12.4, 16.12.4a, 17.2.1, 17.2.1v, 17.2.1EFT, 17.2.1a, 17.2.1r, 17.2.2, 17.3.0.19, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT
External References
Related Security Bulletins