CVE-2020-3480
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the Details section of this advisory.
Múltiples vulnerabilidades en la característica de Zone-Based Firewall del Software IOS XE de Cisco podrían permitir a un atacante remoto no autenticado hacer que el dispositivo se recargue o deje de reenviar el tráfico a través del firewall. Las vulnerabilidades se deben al manejo incompleto de los paquetes de la capa 4 a través del dispositivo. Un atacante podría explotar estas vulnerabilidades enviando una cierta secuencia de patrones de tráfico a través del dispositivo. Una explotación exitosa podría permitir al atacante hacer que el dispositivo recargara o dejara de reenviar el tráfico a través del cortafuegos, lo que resultaría en una denegación de servicio. Para obtener más información sobre estas vulnerabilidades, véase la sección de detalles de este aviso
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2019-12-12 CVE Reserved
- 2020-09-24 CVE Published
- 2023-06-10 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-754: Improper Check for Unusual or Exceptional Conditions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-zbfw-94ckG4G | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1100 Integrated Services Router Search vendor "Cisco" for product "1100 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1101 Integrated Services Router Search vendor "Cisco" for product "1101 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1109 Integrated Services Router Search vendor "Cisco" for product "1109 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1111x Integrated Services Router Search vendor "Cisco" for product "1111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 111x Integrated Services Router Search vendor "Cisco" for product "111x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1120 Integrated Services Router Search vendor "Cisco" for product "1120 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 1160 Integrated Services Router Search vendor "Cisco" for product "1160 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4221 Integrated Services Router Search vendor "Cisco" for product "4221 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4321 Integrated Services Router Search vendor "Cisco" for product "4321 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331 Integrated Services Router Search vendor "Cisco" for product "4331 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4351 Integrated Services Router Search vendor "Cisco" for product "4351 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4431 Integrated Services Router Search vendor "Cisco" for product "4431 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4451-x Integrated Services Router Search vendor "Cisco" for product "4451-x Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | 4461 Integrated Services Router Search vendor "Cisco" for product "4461 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1001-hx Search vendor "Cisco" for product "Asr 1001-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1001-x Search vendor "Cisco" for product "Asr 1001-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1002-hx Search vendor "Cisco" for product "Asr 1002-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1002-x Search vendor "Cisco" for product "Asr 1002-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1004 Search vendor "Cisco" for product "Asr 1004" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1006 Search vendor "Cisco" for product "Asr 1006" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1006-x Search vendor "Cisco" for product "Asr 1006-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1009-x Search vendor "Cisco" for product "Asr 1009-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 1013 Search vendor "Cisco" for product "Asr 1013" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Cloud Services Router 1000v Search vendor "Cisco" for product "Cloud Services Router 1000v" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Integrated Services Virtual Router Search vendor "Cisco" for product "Integrated Services Virtual Router" | - | - |
Safe
|