← Back

CVE-2020-3527

nvd nist
Published: Sep 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of this device. A successful exploit could allow the attacker to crash the device fully before an automatic recovery.

Affected (2)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
2 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Cisco
From 16.12.0 to 16.12.3
From 16.9.0 to 16.9.5
Running on/withPlatform Versions
Cisco
Catalyst C9200l 24p 4g
All versions
Cisco
Catalyst C9200l 24p 4x
All versions
Cisco
Catalyst C9200l 24pxg 2y
All versions
Cisco
Catalyst C9200l 24pxg 4x
All versions
Cisco
Catalyst C9200l 24t 4g
All versions
Cisco
Catalyst C9200l 24t 4x
All versions
Cisco
Catalyst C9200l 48p 4g
All versions
Cisco
Catalyst C9200l 48p 4x
All versions
Cisco
Catalyst C9200l 48pxg 2y
All versions
Cisco
Catalyst C9200l 48pxg 4x
All versions
Cisco
Catalyst C9200l 48t 4g
All versions
Cisco
Catalyst C9200l 48t 4x
All versions

Timeline

No history available yet.