#VU29213 Input validation error in Cisco ASR 5000 Series - CVE-2020-3244
Published: June 23, 2020
Cisco ASR 5000 Series
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the Enhanced Charging Service (ECS) functionality. A remote attacker can send a specially crafted HTTP request, bypass the traffic classification rules and potentially avoid being charged for traffic consumption.