PT-2020-4181 · Cisco · Cisco Ios Xe
Published
2020-09-24
·
Updated
2024-12-19
·
CVE-2020-3359
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers (affected versions not specified)
Cisco IOS XE Software for Cisco Catalyst 9000 Series (affected versions not specified)
Description:
The issue is related to insufficient validation of input data in the multicast DNS (mDNS) feature, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by sending a crafted mDNS packet to an affected device. A successful exploit could cause a device to reload, resulting in a DoS condition.
Recommendations:
For Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers, update to a version that includes the fix for this issue.
For Cisco IOS XE Software for Cisco Catalyst 9000 Series, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the mDNS feature until a patch is available.
Note: Cisco has released software updates that address this vulnerability, and there are no workarounds that address this vulnerability.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe