CVE-2020-3480

HIGH

Cisco IOS XE - Unauthenticated Denial of Service via Zone-Based Firewall Layer 4 Packet Handling

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0116
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
cisco/ios_xe
Published Sep 24, 2020
Tracked Since Feb 18, 2026