PT-2020-2793 · Cisco · Cisco Ios Xe+1

Published

2020-06-03

·

Updated

2021-09-17

·

CVE-2020-3230

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS Software and Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations. The vulnerability is due to incorrect handling of crafted IKEv2 SA-Init packets. An attacker could exploit this vulnerability by sending crafted IKEv2 SA-Init packets to the affected device, causing it to reach the maximum incoming negotiation limits and preventing further IKEv2 security associations from being formed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02888
CVE-2020-3230

Affected Products

Cisco Ios
Cisco Ios Xe