CVE-2020-3363
published 2020-08-17CVE-2020-3363: A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to…
PriorityP349high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.82%
76.2th percentile
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_250_series_smart_switches_software | — | — |
| cisco | small_business_smart_and_managed_switches | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hxc-5mh2-9rxg: A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacke
ghsa_unreviewed·2022-05-24
CVE-2020-3363 [MEDIUM] CWE-20 GHSA-2hxc-5mh2-9rxg: A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacke
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
Cisco
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
vendor_cisco·2020-08-05·CVSS 8.6
CVE-2020-3363 [HIGH] CWE-20 Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition.
This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
Cisco has released software updates that address this vulnerability for devices that have not reached the end of soft
Cisco
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3363 Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
CVE-2020-3363: Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected. Cisco has released software updates that address this vulnerability for devices that have not reached th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-08-17
Published