cbcvebase.
CVE-2020-3527
published 2020-09-24

CVE-2020-3527: A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The…

PriorityP350high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.37%
69.2th percentile
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of this device. A successful exploit could allow the attacker to crash the device fully before an automatic recovery.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocatalyst_9200_series_switches_jumbo_frame
ciscocisco_ios_xe_software
ciscoios_xe>= 16.12.0 < 16.12.316.12.3
ciscoios_xe>= 16.9.0 < 16.9.516.9.5

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.