CVE-2020-3560
published 2020-09-24CVE-2020-3560: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.42%
70.0th percentile
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific port on an affected device. A successful exploit could either allow the attacker to tear down the connection between the AP and the wireless LAN controller, resulting in the affected device not being able to process client traffic, or cause the vulnerable device to reload, triggering a DoS condition. After the attack, the affected device should automatically recover its normal functions without manual intervention.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | access_points | < 16.12.4a | 16.12.4a |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_points_udp_flooding | — | — |
| cisco | business_access_points | >= 10.0 < 10.1.1.0 | 10.1.1.0 |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | wireless_lan_controller | >= 8.9 < 8.10.112.0 | 8.10.112.0 |
| cisco | wireless_lan_controller_software | < 8.5.161.0 | 8.5.161.0 |
| cisco | wireless_lan_controller_software | >= 8.6 < 8.8.130.0 | 8.8.130.0 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
vendor_cisco·2020-09-24·CVSS 8.6
CVE-2020-3560 [HIGH] CWE-400 Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device.
The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific port on an affected device. A successful exploit could either allow the attacker to tear down the connection between the AP and the wireless LAN controller, resulting in the affected device not being able to process client traffic, or cause the vulnerable device to reload, triggering a DoS condition. After the attack, the affected device should automatically recover its
Cisco
Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3560 Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
CVE-2020-3560: Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific port on an affected device. A successful exploit could either allow the attacker to tear down the connection between the AP and the wireless LAN controller, resulting in the affected device not being able to process client traffic, or cause the vulnerable device to reload, triggering a DoS condition. After the attack, the affected device should automaticall
GHSA
GHSA-8grp-f8hg-jmhh: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected
ghsa_unreviewed·2022-05-24
CVE-2020-3560 [HIGH] GHSA-8grp-f8hg-jmhh: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific port on an affected device. A successful exploit could either allow the attacker to tear down the connection between the AP and the wireless LAN controller, resulting in the affected device not being able to process client traffic, or cause the vulnerable device to reload, triggering a DoS condition. After the attack, the affected device should automatically recover its normal functions without manual intervention.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6556 chromium-browser: Heap buffer overflow in SwiftShader
bugzilla·2020-08-19·CVSS 8.8
CVE-2020-6556 [HIGH] CVE-2020-6556 chromium-browser: Heap buffer overflow in SwiftShader
CVE-2020-6556 chromium-browser: Heap buffer overflow in SwiftShader
A heap buffer overflow flaw was found in the SwiftShader component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1115345
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1870007]
Affects: fedora-all [bug 1870006]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/
Bugzilla
CVE-2020-6542 chromium-browser: Use after free in ANGLE
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6542 [HIGH] CVE-2020-6542 chromium-browser: Use after free in ANGLE
CVE-2020-6542 chromium-browser: Use after free in ANGLE
An use after free flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1107433
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6542
Bugzilla
CVE-2020-6547 chromium-browser: Incorrect security UI in media
bugzilla·2020-08-11·CVSS 6.5
CVE-2020-6547 [MEDIUM] CVE-2020-6547 chromium-browser: Incorrect security UI in media
CVE-2020-6547 chromium-browser: Incorrect security UI in media
An incorrect security ui flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1102153
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-654
Bugzilla
CVE-2020-6546 chromium-browser: Inappropriate implementation in installer
bugzilla·2020-08-11·CVSS 7.8
CVE-2020-6546 [HIGH] CVE-2020-6546 chromium-browser: Inappropriate implementation in installer
CVE-2020-6546 chromium-browser: Inappropriate implementation in installer
An inappropriate implementation flaw was found in the installer component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1100280
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/sec
Bugzilla
CVE-2020-6544 chromium-browser: Use after free in media
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6544 [HIGH] CVE-2020-6544 chromium-browser: Use after free in media
CVE-2020-6544 chromium-browser: Use after free in media
An use after free flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1108497
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6544
Bugzilla
CVE-2020-6552 chromium-browser: Use after free in Blink
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6552 [HIGH] CVE-2020-6552 chromium-browser: Use after free in Blink
CVE-2020-6552 chromium-browser: Use after free in Blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1108518
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6552
Bugzilla
CVE-2020-6553 chromium-browser: Use after free in offline mode
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6553 [HIGH] CVE-2020-6553 chromium-browser: Use after free in offline mode
CVE-2020-6553 chromium-browser: Use after free in offline mode
An use after free flaw was found in the offline mode component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1111307
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-655
Bugzilla
CVE-2020-6548 chromium-browser: Heap buffer overflow in Skia
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6548 [HIGH] CVE-2020-6548 chromium-browser: Heap buffer overflow in Skia
CVE-2020-6548 chromium-browser: Heap buffer overflow in Skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1103827
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6548
Bugzilla
CVE-2020-6545 chromium-browser: Use after free in audio
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6545 [HIGH] CVE-2020-6545 chromium-browser: Use after free in audio
CVE-2020-6545 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1095584
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6545
Bugzilla
CVE-2020-6543 chromium-browser: Use after free in task scheduling
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6543 [HIGH] CVE-2020-6543 chromium-browser: Use after free in task scheduling
CVE-2020-6543 chromium-browser: Use after free in task scheduling
An use after free flaw was found in the task scheduling component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1104046
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-20
Bugzilla
CVE-2020-6554 chromium-browser: Use after free in extensions
bugzilla·2020-08-11·CVSS 8.6
CVE-2020-6554 [HIGH] CVE-2020-6554 chromium-browser: Use after free in extensions
CVE-2020-6554 chromium-browser: Use after free in extensions
An use after free flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1094235
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6554
Bugzilla
CVE-2020-6550 chromium-browser: Use after free in IndexedDB
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6550 [HIGH] CVE-2020-6550 chromium-browser: Use after free in IndexedDB
CVE-2020-6550 chromium-browser: Use after free in IndexedDB
An use after free flaw was found in the IndexedDB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1106682
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6550
Bugzilla
CVE-2020-6549 chromium-browser: Use after free in media
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6549 [HIGH] CVE-2020-6549 chromium-browser: Use after free in media
CVE-2020-6549 chromium-browser: Use after free in media
An use after free flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1105426
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6549
Bugzilla
CVE-2020-6551 chromium-browser: Use after free in WebXR
bugzilla·2020-08-11·CVSS 8.8
CVE-2020-6551 [HIGH] CVE-2020-6551 chromium-browser: Use after free in WebXR
CVE-2020-6551 chromium-browser: Use after free in WebXR
An use after free flaw was found in the WebXR component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1107815
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6551
Bugzilla
CVE-2020-6555 chromium-browser: Out of bounds read in WebGL
bugzilla·2020-08-11·CVSS 7.6
CVE-2020-6555 [HIGH] CVE-2020-6555 chromium-browser: Out of bounds read in WebGL
CVE-2020-6555 chromium-browser: Out of bounds read in WebGL
An out of bounds read flaw was found in the WebGL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1105202
External References:
https://chromereleases.googleblog.com/2020/08/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1867957]
Affects: fedora-all [bug 1867956]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:3560 https://access.redhat.com/errata/RHSA-2020:3560
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6555
2020-09-24
Published