CVE-2020-3225

HIGH

Cisco IOS - Unauthenticated Denial of Service via CIP Traffic Processing

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to insufficient input processing of CIP traffic. An attacker could exploit these vulnerabilities by sending crafted CIP traffic to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0103
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (50)
cisco/ios 12.2\(44\)ex
cisco/ios 12.2\(44\)ex1
cisco/ios 12.2\(46\)se1
cisco/ios 12.2\(46\)se2
cisco/ios 12.2\(50\)se
cisco/ios 12.2\(50\)se1
cisco/ios 12.2\(50\)se2
cisco/ios 12.2\(50\)se3
cisco/ios 12.2\(50\)se4
cisco/ios 12.2\(50\)se5
... and 40 more
Published Jun 03, 2020
Tracked Since Feb 18, 2026