CVE-2020-3465

HIGH

Cisco IOS XE - Unauthenticated Denial of Service via Ethernet Frame Handling

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this vulnerability by sending the Ethernet frames onto the Ethernet segment. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0023
EPSS Percentile 46.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
cisco/ios_xe 16.6.9
cisco/ios_xe 17.4.1
Published Sep 24, 2020
Tracked Since Feb 18, 2026