← Back

CVE-2020-3353

nvd nist
Published: Jun 3, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may occur when syslog messages are processed. An attacker could exploit this vulnerability by sending a high rate of syslog messages to an affected device. A successful exploit could allow the attacker to cause the Application Server process to crash, resulting in a DoS condition.

Affected (21)

1 product
Identity Services Engine
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 2.2.0.470
Version 2.2.0.470 patch10
Version 2.2.0.470 patch11
Version 2.2.0.470 patch12
Version 2.2.0.470 patch1
Version 2.2.0.470 patch2
Version 2.2.0.470 patch3
Version 2.2.0.470 patch4
Version 2.2.0.470 patch5
Version 2.2.0.470 patch6
Version 2.2.0.470 patch7
Version 2.2.0.470 patch8
Version 2.2.0.470 patch9
Version 2.3.0.298
Version 2.3.0.298 patch1
Version 2.3.0.298 patch2
Version 2.3.0.298 patch3
Version 2.3.0.298 patch4
Version 2.3.0.298 patch5
Version 2.4.0.357
Version 2.4.0.357 patch1

Timeline

No history available yet.