Vulnerability identifier: #VU47240
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3422
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perofrm a denial of service (DoS) attack.
The vulnerability exists due to the IP Service Level Agreement (SLA) responder feature could consume a port that could be used by another feature. A remote attacker can send specific IP SLA control packets and cause an in-use port to be consumed by the IP SLA responder, resulting in a denial of service condition.
Affected software
Cisco IOS XE
How to mitigate CVE-2020-3422
Install updates from vendor's website.
Cisco IOS XE - addressed in versions Amsterdam 17.1.2, Amsterdam 17.2.1, Amsterdam 17.2.2, Fuji 16.9.6, 16.3.11, 16.6.8, 16.9.5.72, 16.9.6, 16.12.3, 16.12.3s, 16.12.4, 16.12.4a, 17.1.1.58, 17.1.2, 17.2.0.49, 17.2.0.55, 17.2.1, 17.2.1v, 17.2.1.31, 17.2.2, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT
External References
Related Security Bulletins