State Issues in Cisco IOS XE - CVE-2020-3422

 

State Issues in Cisco IOS XE - CVE-2020-3422

Published: September 24, 2020 / Updated: October 1, 2020


Vulnerability identifier: #VU47240
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3422
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perofrm a denial of service (DoS) attack.

The vulnerability exists due to the IP Service Level Agreement (SLA) responder feature could consume a port that could be used by another feature. A remote attacker can send specific IP SLA control packets and cause an in-use port to be consumed by the IP SLA responder, resulting in a denial of service condition. 


Affected software

Cisco IOS XE

How to mitigate CVE-2020-3422

Install updates from vendor's website.

Cisco IOS XE - addressed in versions Amsterdam 17.1.2, Amsterdam 17.2.1, Amsterdam 17.2.2, Fuji 16.9.6, 16.3.11, 16.6.8, 16.9.5.72, 16.9.6, 16.12.3, 16.12.3s, 16.12.4, 16.12.4a, 17.1.1.58, 17.1.2, 17.2.0.49, 17.2.0.55, 17.2.1, 17.2.1v, 17.2.1.31, 17.2.2, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT

External References

Related Security Bulletins