CVE-2020-3527

HIGH

Cisco IOS XE 16.9.0-16.9.4 - Unauthenticated Denial of Service via Oversized Frames

Title source: llm
STIX 2.1

Description

A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of this device. A successful exploit could allow the attacker to crash the device fully before an automatic recovery.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0068
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-20
Status published
Products (1)
cisco/ios_xe 16.9.0 - 16.9.5
Published Sep 24, 2020
Tracked Since Feb 18, 2026