HIGH✓ PATCH🇬🇧 English

CVE-2020-3510

CVSS 8.6v3.1pub. 2020-09-24upd. 2024-11-21

A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vulnerability is due to insufficient error handling when parsing DNS requests. An attacker could exploit this vulnerability by sending a series of malicious DNS requests to an Umbrella Connector client interface of an affected device. A successful exploit could allow the attacker to cause a crash of the iosd process, which triggers a reload of the affected device.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco Catalyst C9200 24p

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200 24t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200 48p

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200 48t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24p 4g

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24p 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24pxg 2y

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24pxg 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24t 4g

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 24t 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48p 4g

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48p 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48pxg 2y

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48pxg 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48t 4g

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9200l 48t 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 24p

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 24s

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 24t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 24u

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 24ux

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48p

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48s

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48u

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48un

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300 48uxm

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300l 24p 4g

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300l 24p 4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst C9300l 24t 4g

    HW
    Cisco
    wszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)

CVE-2026-20272CRITICAL9.8PL ✓ten sam produkt

Cisco IOS XE — improper neutralization of special elements (CWE-74)