CVE-2020-3516
published 2020-09-24CVE-2020-3516: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device…
PriorityP426medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.67%
74.2th percentile
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | < 16.9.6 | 16.9.6 |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | >= 16.12.0 < 16.12.2 | 16.12.2 |
| cisco | ios_xe | >= 17.1.0 < 17.1.1 | 17.1.1 |
| nokogiri | nokogiri | >= 0 < 1.11.4 | 1.11.4 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
ghsa7.5HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c38h-42jg-3h9q: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the
ghsa_unreviewed·2022-05-24
CVE-2020-3516 [MEDIUM] GHSA-c38h-42jg-3h9q: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server.
GHSA
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
ghsa·2021-05-17·CVSS 7.5
CVE-2019-20388 [HIGH] Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
### Summary
Nokogiri v1.11.4 updates the vendored libxml2 from v2.9.10 to v2.9.12 which addresses:
- [CVE-2019-20388](https://security.archlinux.org/CVE-2019-20388) (Medium severity)
- [CVE-2020-24977](https://security.archlinux.org/CVE-2020-24977) (Medium severity)
- [CVE-2021-3517](https://security.archlinux.org/CVE-2021-3517) (Medium severity)
- [CVE-2021-3518](https://security.archlinux.org/CVE-2021-3518) (Medium severity)
- [CVE-2021-3537](https://security.archlinux.org/CVE-2021-3537) (Low severity)
- [CVE-2021-3541](https://security.archlinux.org/CVE-2021-3541) (Low severity)
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.or
CISA ICS
Rockwell Automation Stratix Devices Containing Cisco IOS
cisa_ics·2022-10-27·CVSS 7.7
[HIGH] Rockwell Automation Stratix Devices Containing Cisco IOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Devices Containing Cisco IOS
Last RevisedOctober 27, 2022
Alert CodeICSA-22-300-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: Stratix Devices
- Vulnerabilities: Incorrect Authorization, Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Interpretation Conflict, OS Command Injection, Improper Verification of Cryptographic Signature, Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could l
Cisco
Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
vendor_cisco·2020-09-24·CVSS 4.3
CVE-2020-3516 [MEDIUM] CWE-20 Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device.
The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security
Cisco
Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3516 Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
CVE-2020-3516: Cisco IOS XE Software Web UI Improper Input Validation Vulnerability
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvr73955
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-24
Published