Input validation error in Cisco IOS and Cisco IOS XE - CVE-2023-20080
Published: March 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the IPv6 DHCP version 6 (DHCPv6) relay and server features. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Cisco IOS XE
How to mitigate CVE-2023-20080
Cisco IOS XE - addressed in versions Amsterdam-17.3.4, Bengaluru-17.5.1, Bengaluru-17.6.1, Gibraltar-16.12.8, 15.2(04)E10d, 15.2(07)E07, 15.8(03)M09, 15.9(03)M06, 16.12(6.165), 16.12.8, 17.3(3.8), 17.3.4, 17.3.4c, 17.3.4a, 17.3.4 b, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.5(0.143), 17.5.1, 17.5.1a, 17.5.1b, 17.6(0.18), 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.7.1, 17.7.1a, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.10.1, 17.10.1a, 17.10.1b