CVE-2020-3500
Cisco StarOS IPv6 Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to an affected device with the goal of reaching the vulnerable section of the input buffer. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
Una vulnerabilidad en la implementación de IPv6 de Cisco StarOS podría permitir a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) sobre un dispositivo afectado. La vulnerabilidad es debido a una comprobación insuficiente del tráfico IPv6 entrante. Un atacante podría explotar esta vulnerabilidad mediante el envío de un paquete IPv6 diseñado hacia un dispositivo afectado con el objetivo de llegar a la sección vulnerable del búfer de entrada. Una explotación con éxito podría permitir al atacante causar que el dispositivo se recargue, resultando en una condición de DoS. Esta vulnerabilidad es específica del tráfico IPv6. El tráfico IPv4 no está afectado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-08-17 CVE Published
- 2023-05-03 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Staros Search vendor "Cisco" for product "Staros" | < 21.18.3 Search vendor "Cisco" for product "Staros" and version " < 21.18.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Virtualized Packet Core-single Instance Search vendor "Cisco" for product "Virtualized Packet Core-single Instance" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Staros Search vendor "Cisco" for product "Staros" | < 21.18.3 Search vendor "Cisco" for product "Staros" and version " < 21.18.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 5500 Search vendor "Cisco" for product "Asr 5500" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Staros Search vendor "Cisco" for product "Staros" | < 21.18.3 Search vendor "Cisco" for product "Staros" and version " < 21.18.3" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr 5700 Search vendor "Cisco" for product "Asr 5700" | - | - |
Safe
|