CVE-2020-3244

MEDIUM

Cisco StarOS < 21.18.0 - Unauthenticated Traffic Classification Bypass via Malformed HTTP Request

Title source: llm
STIX 2.1

Description

A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attacker could exploit this vulnerability by sending a malformed HTTP request to an affected device. A successful exploit could allow the attacker to bypass the traffic classification rules and potentially avoid being charged for traffic consumption.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
cisco/staros < 21.18.0
Published Jun 18, 2020
Tracked Since Feb 18, 2026