PT-2020-2981 · Cisco · Cisco Asr 5000 Series Aggregation Services Routers

Published

2020-06-16

·

Updated

2021-09-17

·

CVE-2020-3244

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco ASR 5000 Series Aggregation Services Routers (affected versions not specified)
Description A vulnerability in the Enhanced Charging Service (ECS) functionality could allow an unauthenticated, remote attacker to bypass traffic classification rules on an affected device. The issue is due to insufficient input validation of user traffic. An attacker could exploit this by sending a malformed HTTP request to an affected device, potentially allowing them to bypass traffic classification rules and avoid being charged for traffic consumption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03148
BDU:2020-03150
CVE-2020-3244

Affected Products

Cisco Asr 5000 Series Aggregation Services Routers