CVE-2020-3480
published 2020-09-24CVE-2020-3480: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.40%
69.7th percentile
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
vendor_cisco·2020-09-24·CVSS 8.6
CVE-2020-3421 [HIGH] CWE-754 Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall.
The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address the
Cisco
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3480 Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
CVE-2020-3480: Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-754, CWE-754
Bug IDs: CSCvs71952, CSCvt52986, CSCvs71
GHSA
GHSA-j8wq-qrfv-42q5: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the devi
ghsa_unreviewed·2022-05-24
CVE-2020-3480 [HIGH] CWE-754 GHSA-j8wq-qrfv-42q5: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the devi
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sending a certain sequence of traffic patterns through the device. A successful exploit could allow the attacker to cause the device to reload or stop forwarding traffic through the firewall, resulting in a denial of service. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
Talos
Threat Source newsletter for Oct. 8, 2020
blogs_talos·2020-10-08
Threat Source newsletter for Oct. 8, 2020
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
We’ve been writing and talking about election security a ton lately. And as the U.S. presidential election draws closer, we decided it was time to summarize some things. So, we released this blog post with our formal recommendations for voters and how they can avoid disinformation and other bad actors trying to influence the election.
Our researchers are also following the development of the PoetRAT malware. This remote access trojan is still targeting public and private entities in Azerbaijan, and we’ve seen the actor behind the threat make several tweaks over time to make it more agile and difficult to detect.
If vulnerability research is more your thing, we also have a deep dive into our work discovering bugs in Micr
Talos
Threat Source newsletter for Oct. 8, 2020
blogs_talos·2020-10-08
Threat Source newsletter for Oct. 8, 2020
## Threat Source newsletter for Oct. 8, 2020
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
We’ve been writing and talking about election security a ton lately. And as the U.S. presidential election draws closer, we decided it was time to summarize some things. So, we released this blog post with our formal recommendations for voters and how they can avoid disinformation and other bad actors trying to influence the election.
Our researchers are also following the development of the PoetRAT malware . This remote access trojan is still targeting public and private entities in Azerbaijan, and we’ve seen the actor behind the threat make several tweaks over time to make it more agile and difficult to detect.
If vulnerability research is more your thing, we also have a d
Talos
Threat Source newsletter for Oct. 1, 2020
blogs_talos·2020-10-01
Threat Source newsletter for Oct. 1, 2020
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
In the past, we’ve covered what disinformation (otherwise known as “fake news”) is and who spreads it. Now, we’re diving into why it works, and why it’s so easy for people to spread. Check out our full paper here to gain a lot of insight into the psychology of social media.
On the malware front, we also have an update on LodaRAT. We've seen several new variants of this threat in the wild. Here’s what to look out for and how to protect your network.
### UPCOMING PUBLIC ENGAGEMENTS
Event: A double-edged sword: The threat of dual-use tools
Location: Cisco Webex webinar
Date: Oct. 8 at 11 a.m. ET
Speakers: Edmund Brumaghin
Synopsis: It's difficult to read any information security news lately without hearing about large cor
Talos
Threat Source newsletter for Oct. 1, 2020
blogs_talos·2020-10-01
Threat Source newsletter for Oct. 1, 2020
## Threat Source newsletter for Oct. 1, 2020
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
In the past, we’ve covered what disinformation (otherwise known as “fake news”) is and who spreads it. Now, we’re diving into why it works, and why it’s so easy for people to spread. Check out our full paper here to gain a lot of insight into the psychology of social media.
On the malware front, we also have an update on LodaRAT. We've seen several new variants of this threat in the wild. Here’s what to look out for and how to protect your network.
## UPCOMING PUBLIC ENGAGEMENTS
Event: A double-edged sword: The threat of dual-use tools Location: Cisco Webex webinar Date: Oct. 8 at 11 a.m. ET Speakers: Edmund Brumaghin Synopsis: It's difficult to read any information securit
2020-09-24
Published