CVE-2020-3231
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2020
Last modified:
08/06/2020
Description
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could allow an unauthenticated, adjacent attacker to forward broadcast traffic before being authenticated on the port. The vulnerability exists because broadcast traffic that is received on the 802.1X-enabled port is mishandled. An attacker could exploit this vulnerability by sending broadcast traffic on the port before being authenticated. A successful exploit could allow the attacker to send and receive broadcast traffic on the 802.1X-enabled port before authentication.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Base Score 2.0
2.90
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cisco:ios:15.2\(5\)e2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(5\)ex:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(5a\)e:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(5b\)e:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(5c\)e:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e0c:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e1a:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e1s:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e2b:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e3:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(6\)e4:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios:15.2\(7\)e:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page