PT-2020-2794 · Cisco · Cisco Ios Xe+1

Published

2020-06-03

·

Updated

2021-09-17

·

CVE-2020-3225

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified)
Description The issue is related to the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software and Cisco IOS XE Software. It is caused by insufficient input processing of CIP traffic, which could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. An attacker could exploit this by sending crafted CIP traffic to be processed by an affected device.
Recommendations For Cisco IOS Software, update to a version that addresses these vulnerabilities. For Cisco IOS XE Software, update to a version that addresses these vulnerabilities. As a temporary workaround, consider restricting access to CIP traffic to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02889
CVE-2020-3225

Affected Products

Cisco Ios
Cisco Ios Xe