CVE-2020-3363

HIGHCVSS 8.6/10EPSS 1.82%

Last modified

CVE-2020-3363 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. EPSS estimates a 1.82% chance of exploitation in the next 30 days.

Description

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

Metrics

CVSS 3.1
8.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

EPSS Probability
1.82%

76.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoSg250x-24 FirmwareAll versions
CiscoSg250x-24p FirmwareAll versions
CiscoSg250x-48 FirmwareAll versions
CiscoSg250x-48p FirmwareAll versions
CiscoSg250-08 FirmwareAll versions
CiscoSg250-08hp FirmwareAll versions
CiscoSg250-10p FirmwareAll versions
CiscoSg250-18 FirmwareAll versions
CiscoSg250-26 FirmwareAll versions
CiscoSg250-26hp FirmwareAll versions
CiscoSg250-26p FirmwareAll versions
CiscoSg250-50 FirmwareAll versions
CiscoSg250-50hp FirmwareAll versions
CiscoSg250-50p FirmwareAll versions
CiscoSf250-24 FirmwareAll versions
CiscoSf250-24p FirmwareAll versions
CiscoSf250-48 FirmwareAll versions
CiscoSf250-48hp FirmwareAll versions
CiscoSg350-10 FirmwareAll versions
CiscoSg350-10p FirmwareAll versions
CiscoSg350-10mp FirmwareAll versions
CiscoSg355-10p FirmwareAll versions
CiscoSg350-28 FirmwareAll versions
CiscoSg350-28p FirmwareAll versions
CiscoSg350-28mp FirmwareAll versions
CiscoSf350-48 FirmwareAll versions
CiscoSf350-48p FirmwareAll versions
CiscoSf350-48mp FirmwareAll versions
CiscoSg350xg-2f10 FirmwareAll versions
CiscoSg350xg-24f FirmwareAll versions
CiscoSg350xg-24t FirmwareAll versions
CiscoSg350xg-48t FirmwareAll versions
CiscoSg350x-24 FirmwareAll versions
CiscoSg350x-24p FirmwareAll versions
CiscoSg350x-24mp FirmwareAll versions
CiscoSg350x-48 FirmwareAll versions
CiscoSg350x-48p FirmwareAll versions
CiscoSg350x-48mp FirmwareAll versions
CiscoSx550x-16ft FirmwareAll versions
CiscoSx550x-24ft FirmwareAll versions
CiscoSx550x-12f FirmwareAll versions
CiscoSx550x-24f FirmwareAll versions
CiscoSx550x-24 FirmwareAll versions
CiscoSx550x-52 FirmwareAll versions
CiscoSg550x-24 FirmwareAll versions
CiscoSg550x-24p FirmwareAll versions
CiscoSg550x-24mp FirmwareAll versions
CiscoSg550x-24mpp FirmwareAll versions
CiscoSg550x-48 FirmwareAll versions
CiscoSg550x-48p FirmwareAll versions

Showing 50 of 114 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-3363?
A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.
How severe is CVE-2020-3363?
CVE-2020-3363 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 1.82% probability of exploitation in the next 30 days.
How do I fix CVE-2020-3363?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-3363?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST