Input validation error in Cisco IOS and Cisco IOS XE - CVE-2023-20080

 

Input validation error in Cisco IOS and Cisco IOS XE - CVE-2023-20080

Published: March 23, 2023


Vulnerability identifier: #VU73983
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20080
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the IPv6 DHCP version 6 (DHCPv6) relay and server features. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Cisco IOS
Cisco IOS XE

How to mitigate CVE-2023-20080

Install updates from vendor's website.

Cisco IOS - addressed in versions 15.2(04)E10d, 15.2(7)E7, 15.8(03)M09, 15.9(3)M6, 16.12(6.165), 16.12.8, 17.3(3.8), 17.3.4, 17.3.4c, 17.3.4a, 17.3.4b, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.5(0.143), 17.5.1, 17.5.1a, 17.5.1b, 17.6(0.18), 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.7.1, 17.7.1a, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.10.1, 17.10.1a, 17.10.1b
Cisco IOS XE - addressed in versions Amsterdam-17.3.4, Bengaluru-17.5.1, Bengaluru-17.6.1, Gibraltar-16.12.8, 15.2(04)E10d, 15.2(07)E07, 15.8(03)M09, 15.9(03)M06, 16.12(6.165), 16.12.8, 17.3(3.8), 17.3.4, 17.3.4c, 17.3.4a, 17.3.4 b, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.5(0.143), 17.5.1, 17.5.1a, 17.5.1b, 17.6(0.18), 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.7.1, 17.7.1a, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.10.1, 17.10.1a, 17.10.1b

External References

Related Security Bulletins