PT-2020-2897 · Cisco · Cisco Asr 920 Series Aggregation Services Router+1

Published

2020-06-03

·

Updated

2021-10-19

·

CVE-2020-3232

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco ASR 920 Series Aggregation Services Router model ASR920-12SZ-IM (affected versions not specified)
Description The issue is related to the Simple Network Management Protocol (SNMP) implementation, specifically due to incorrect handling of data returned for Cisco Discovery Protocol queries to SNMP. An authenticated, remote attacker could exploit this by sending a request for Cisco Discovery Protocol information using SNMP, potentially causing the device to reload and resulting in a denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03054
CVE-2020-3232

Affected Products

Cisco Asr 920 Series Aggregation Services Router
Cisco Ios Xe