imPC@ndo IT

Tracker / CVE-2020-3496

CVE-2020-3496

Medium 5.3

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the switch management CLI to stop responding, resulting in a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

Affected products and versions

cisco sf200-24_firmware · … → 2.5.5.47
cisco sf200-24fp_firmware · … → 2.5.5.47
cisco sf200-24p_firmware · … → 2.5.5.47
cisco sf200-48_firmware · … → 2.5.5.47
cisco sf200-48p_firmware · … → 2.5.5.47
cisco sf250-24_firmware · … → 2.5.5.47
cisco sf250-24p_firmware · … → 2.5.5.47
cisco sf250-48_firmware · … → 2.5.5.47
cisco sf250-48hp_firmware · … → 2.5.5.47
cisco sf300-08_firmware · … → 2.5.5.47
cisco sf300-24_firmware · … → 2.5.5.47
cisco sf300-24mp_firmware · … → 2.5.5.47
cisco sf300-24p_firmware · … → 2.5.5.47
cisco sf300-24pp_firmware · … → 2.5.5.47
cisco sf300-48_firmware · … → 2.5.5.47
cisco sf300-48p_firmware · … → 2.5.5.47
cisco sf300-48pp_firmware · … → 2.5.5.47
cisco sf302-08_firmware · … → 2.5.5.47
cisco sf302-08mp_firmware · … → 2.5.5.47
cisco sf302-08mpp_firmware · … → 2.5.5.47
cisco sf302-08p_firmware · … → 2.5.5.47
cisco sf302-08pp_firmware · … → 2.5.5.47
cisco sf350-48_firmware · … → 2.5.5.47
cisco sf350-48mp_firmware · … → 2.5.5.47
cisco sf350-48p_firmware · … → 2.5.5.47
cisco sf500-24_firmware · … → 2.5.5.47
cisco sf500-24p_firmware · … → 2.5.5.47
cisco sf500-48_firmware · … → 2.5.5.47
cisco sf500-48p_firmware · … → 2.5.5.47
cisco sf550x-24_firmware · … → 2.5.5.47
cisco sf550x-24mp_firmware · … → 2.5.5.47
cisco sf550x-24p_firmware · … → 2.5.5.47
cisco sf550x-48_firmware · … → 2.5.5.47
cisco sf550x-48mp_firmware · … → 2.5.5.47
cisco sf550x-48p_firmware · … → 2.5.5.47
cisco sg200-08_firmware · … → 2.5.5.47
cisco sg200-08p_firmware · … → 2.5.5.47
cisco sg200-10fp_firmware · … → 2.5.5.47
cisco sg200-18_firmware · … → 2.5.5.47
cisco sg200-26_firmware · … → 2.5.5.47
cisco sg200-26fp_firmware · … → 2.5.5.47
cisco sg200-26p_firmware · … → 2.5.5.47
cisco sg200-50_firmware · … → 2.5.5.47
cisco sg200-50fp_firmware · … → 2.5.5.47
cisco sg200-50p_firmware · … → 2.5.5.47
cisco sg250-08_firmware · … → 2.5.5.47
cisco sg250-08hp_firmware · … → 2.5.5.47
cisco sg250-10p_firmware · … → 2.5.5.47
cisco sg250-18_firmware · … → 2.5.5.47
cisco sg250-26_firmware · … → 2.5.5.47
cisco sg250-26hp_firmware · … → 2.5.5.47
cisco sg250-26p_firmware · … → 2.5.5.47
cisco sg250-50_firmware · … → 2.5.5.47
cisco sg250-50hp_firmware · … → 2.5.5.47
cisco sg250-50p_firmware · … → 2.5.5.47
cisco sg250x-24_firmware · … → 2.5.5.47
cisco sg250x-24p_firmware · … → 2.5.5.47
cisco sg250x-48_firmware · … → 2.5.5.47
cisco sg250x-48p_firmware · … → 2.5.5.47
cisco sg300-10_firmware · … → 2.5.5.47

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References