CVE-2020-3363

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/08/2020
Last modified:
06/08/2021

Description

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:sg250x-24_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250x-24:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250x-24p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250x-24p:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250x-48_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250x-48:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250x-48p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250x-48p:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250-08_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250-08:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250-08hp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250-08hp:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250-10p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sg250-10p:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:sg250-18_firmware:-:*:*:*:*:*:*:*