cbcvebase.
CVE-2020-3516
published 2020-09-24

CVE-2020-3516: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device…

PriorityP426medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.67%
74.2th percentile
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A successful exploit could allow the attacker to crash the web server on the device, which must be manually recovered by disabling and re-enabling the web server.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software
ciscoios_xe< 16.9.616.9.6
ciscoios_xe
ciscoios_xe
ciscoios_xe>= 16.12.0 < 16.12.216.12.2
ciscoios_xe>= 17.1.0 < 17.1.117.1.1
nokogirinokogiri>= 0 < 1.11.41.11.4

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
ghsa7.5HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.